Published Product3 min read
ProjectDiscovery meters the scan: Neo 1.0 sells validation by the unit
Neo 1.0 ships autonomous vulnerability discovery and validation on consumption pricing, routing confirmed findings into GitHub, Jira and Linear. The interesting part is not the AI.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- ProjectDiscovery's Neo 1.0 uses AI-driven autonomous security testing to discover, validate and prioritize exploitable vulnerabilities.
- Neo is available through a consumption-based cloud model designed to lower the cost of continuous security testing.
- ProjectDiscovery CEO Rishi Sharma said version 1.0 of Neo is available via a cloud service that makes it possible for DevSecOps teams to run tests and conduct investigations using a consumption-based pricing model.
- Neo 1.0 adds integrations with GitHub, Jira, Confluence, Slack, Linear, APIs, webhooks and the Model Context Protocol (MCP).
- Neo is used to detect, validate and route vulnerabilities to the responsible developer.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
ProjectDiscovery has released version 1.0 of Neo, an autonomous security testing platform that uses AI to discover, validate and prioritize exploitable vulnerabilities [1]. It is sold through a consumption-based cloud model that the company positions as a way to lower the cost of continuous security testing [2], with results wired into GitHub, Jira, Confluence, Slack, Linear, APIs, webhooks and the Model Context Protocol [4].
That combination is the actual product decision. CEO Rishi Sharma said the cloud service lets DevSecOps teams run tests and conduct investigations under consumption pricing [3], which converts a security testing platform from a seat-and-contract purchase into a per-use line item. The workflow integrations are what make that billing shape tolerable: Neo detects, validates and routes vulnerabilities to the developer responsible for the code [5], so the unit being consumed produces a ticket rather than a dashboard entry someone has to triage.
Underneath sits work that is already in the open. ProjectDiscovery also provides access to Nuclei, an open source scanner driven by customizable YAML templates for misconfigurations and exploits [6], plus Subfinder for subdomain discovery, httpx for HTTP probing, Katana for crawling and Naabu for port scanning [7]. Neo itself is built on an open source AI testing framework [18]. The practical read is that the meter is not on scanning, which teams can already run themselves, but on the autonomous validation and routing layer stacked on top [19]. Sharma puts the community at more than 100,000 practitioners [8], which is a distribution advantage for converting existing users into metered ones.
The pitch against incumbents is volume control. Mitch Ashley, vice president and practice lead for software lifecycle engineering at the Futurum Group, said there has never been a shortage of vulnerability findings, and that teams drown in them while burning triage time separating real threats from noise [13][14]. Ashley credited Neo with validating what it finds and routing only exploitable issues to the code owner [15], and argued the scan-and-fix cycle was built for human code at human speed, while AI writes and exploits faster than weekly scans keep up [16]. Sharma made the same point from the other direction: code scanning alone is no longer enough, and without a toolchain that establishes which vulnerabilities are reachable and abusable, teams get overwhelmed by false positives generated by AI models [10]. He also said the cost of applying AI to code testing has historically been too high for many organizations to adopt [11], and that application security in the AI era requires new processes, not just prompting a model to find bugs [12].
Neo can generate alerts continuously in real time or run tests on a schedule [9]. That is where consumption pricing gets uncomfortable: continuous mode means the invoice tracks code velocity, and code velocity is the thing everyone says is accelerating. The devops.com report does not state Neo's rates or the unit being billed [17], so "lower total cost" remains a claim about billing structure rather than a number anyone can model.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
ProjectDiscovery's Neo 1.0 uses AI-driven autonomous security testing to discover, validate and prioritize exploitable vulnerabilities.
ReportedView cited source - [2]
Neo is available through a consumption-based cloud model designed to lower the cost of continuous security testing.
ReportedView cited source - [3]
ProjectDiscovery CEO Rishi Sharma said version 1.0 of Neo is available via a cloud service that makes it possible for DevSecOps teams to run tests and conduct investigations using a consumption-based pricing model.
- [4]
Neo 1.0 adds integrations with GitHub, Jira, Confluence, Slack, Linear, APIs, webhooks and the Model Context Protocol (MCP).
ReportedView cited source - [5]
Neo is used to detect, validate and route vulnerabilities to the responsible developer.
ReportedView cited source - [6]
ProjectDiscovery provides access to Nuclei, an open source vulnerability scanner driven by customizable YAML templates to detect misconfigurations and exploits.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- devops.comMike VizardAug 13ProjectDiscovery Brings Open Source AI Testing to Vulnerability Discovery
Cited in this coverage: Rishi Sharma, CEO, ProjectDiscovery, via devops.com
Cited in this coverage: Mitch Ashley, Futurum Group, via devops.com



