About

Patch disclosed CVEs before public disclosure. Make the loop boring.

ZeroPatch runs an AI patch loop on your production dependency graph. Same-day drafts when an advisory drops, pre-disclosure work on emerging ones, and pull requests your reviewers can bless. The mission is simple — close the gap between "a CVE exists" and "a CVE is fixed in your code" so the window stops being your incident response plan.

The team

A small founding crew running the loop.

ZeroPatch is a small founding team. Engineers who ship the agent and the auto-merge pipeline, the product lead who shapes the cohort experience, and security researchers who audit every auto-merged commit before it reaches a partner repo.

Founder / Engineering

Builds and operates the remediation loop. Owns the agent architecture and the dependency-graph ingestion pipeline.

Founder / Product

Shapes the cohort experience and partner roadmap. Translates security-team workflows into the product surface.

Engineering

Designs the patch-draft reasoning loop and the auto-merge pipeline. Ships the pre-disclosure tracker that watches the edge of disclosure.

Security research

Triages incoming advisories, scores severity against your graph, and audits every auto-merged commit before it reaches your repo.

We publish every patch we ship.

ZeroPatch's public audit log lists every auto-merged CVE advisory fix from the last 90 days — the CVE identifier, severity, the merge commit SHA, and a link to the diff. If we say we shipped it, you can verify it without an NDA.