What Horizon3's $2 Billion Valuation Tells Contractors About the New Baseline for Software Security
Most field-service contractors don't think of themselves as cybersecurity targets. They run HVAC calls, manage electrical projects, coordinate mechanical crews. But if your business runs on cloud software, files permits electronically, invoices customers through an integrated platform, and stores payroll data somewhere other than a filing cabinet, you are operating in a threat environment that is more serious than it was even two years ago.
The software companies you rely on know this. The question is whether they are keeping pace with how fast that environment is changing.
What Happened: Horizon3 Raises $250 Million at a $2 Billion Valuation
On August 3, 2026, TechCrunch reported that San Francisco-based Horizon3 closed a $250 million Series E round, pushing its valuation from $650 million to over $2 billion in just over a year. The round was oversubscribed and co-led by NightDragon and NEA, with seven new investors joining including Singapore's EDBI, defense contractor SAIC, and Qualcomm Ventures.
Horizon3 builds a platform called NodeZero. Instead of scheduling a human penetration test once a year, NodeZero autonomously attacks a company's own production environment on a continuous basis, finds exploitable vulnerabilities, provides remediation guidance, and then verifies that the fixes actually worked. The company has roughly 7,200 to 7,300 customers and is using the capital to expand into Australia, Singapore, and EMEA while scaling its enterprise and federal go-to-market.
That is a remarkable trajectory. And the signal it sends is not subtle: continuous, AI-driven security validation is no longer a nice-to-have for forward-looking tech companies. It is becoming a standard operating expectation.
Why This Story Matters to a Contractor Running an Ops Platform
Here is the direct line from Horizon3's fundraise to your business.
The software platforms your team uses every day, for quoting, dispatching, managing change orders, running project financials, storing crew timesheets and HR records, all of that lives in cloud environments that need to be actively defended. Not defended once a year after a consultant runs a pen test and emails a PDF report. Defended continuously, because the attack surface does not stop changing.
When a security company with Horizon3's specific thesis (replace the annual pen test with autonomous, continuous validation) reaches a $2 billion valuation in just over a year, it means the market has confirmed that the old model is inadequate and that the new model works at scale. It also means the underlying AI capabilities that make continuous security validation affordable are now mature enough to deploy across thousands of customers.
As a contractor, you do not need to become a security expert. But you do need to ask better questions of the software vendors you trust with your operational data.
What "Sensitive Contractor Data" Actually Means
It is easy to abstract away "data" until you think about what is actually in an ops platform. For a 50-person mechanical contractor running mixed service and project work, that typically includes:
- Customer contact and billing information for every account in the CRM
- Quoted and contracted values, including margin data you would not share with competitors
- Subcontractor agreements, POs, and AP records that contain pricing relationships
- Employee timesheets, payroll export files, and HR records
- Permit documentation with site details and compliance information
- Bank-linked invoicing and payment data, especially if the platform connects to QuickBooks or Xero
A breach of any of those categories is not a hypothetical inconvenience. It is a regulatory exposure (particularly in Canada under PIPEDA and provincial privacy law), a customer trust problem, and in some cases a direct financial loss. Insurance carriers are already asking more pointed questions about software security at renewal time for trade contractors.
The Annual Pen Test Is Not Enough Anymore
The traditional model worked like this: hire a security firm, schedule a test window, get a report, patch the findings, repeat next year. That cycle made sense when software environments were more static and attack methods evolved slowly.
Neither of those conditions holds today. Cloud-connected platforms update continuously. Third-party integrations (payment processors, document storage, SMS gateways, accounting APIs) expand the attack surface every time a new connector goes live. AI-generated phishing and credential-stuffing attacks do not wait for your fiscal year to end.
Horizon3's growth to 7,200-plus customers is evidence that organizations of all sizes have accepted this reality and started acting on it. The interesting thing about their model is that it mirrors something contractors already understand intuitively: reactive maintenance is more expensive than planned, ongoing maintenance. You would not tell a facilities customer to inspect their mechanical systems once a year and ignore everything in between. The same logic applies to software security.
Three Questions to Ask Your Software Vendor (That Most Contractors Never Do)
You do not need to run your own penetration test or hire a CISO. But the next time you are evaluating an ops platform, or reviewing your current one at renewal, these questions are worth asking directly:
1. How frequently is your infrastructure tested for vulnerabilities?
A credible answer describes continuous monitoring and automated scanning, not an annual third-party audit. Ask whether they distinguish between discovering vulnerabilities and verifying that remediation actually worked.
2. Where does my data live, and who has access to it?
For Canadian contractors, data residency matters under federal and provincial privacy law. Cloud infrastructure hosted on major providers (Google Cloud, AWS, Azure) with Canadian or North American data regions is a reasonable baseline. Ask whether data is encrypted at rest and in transit, and whether access controls are role-based.
3. What is your incident response process?
If something goes wrong, how quickly will you know? What are your obligations to notify customers? A vendor that has thought seriously about this will have a documented answer. One that has not will give you a vague one.
These are not gotcha questions. They are the kind of questions a well-run vendor will be glad you asked, because it means you are a serious operator.
What This Means in Practice for a Platform Like PolarPath
PolarPath runs on Google Cloud and connects to QuickBooks, Xero, Google Workspace, and Twilio. It handles the full operational execution layer for field-service and project businesses: customer intake, quoting, dispatch, field work orders, project management, change orders, invoicing, timesheets, HR records, and payroll export.
That scope is exactly why security posture is not an afterthought. When one platform connects that many operational functions and touches that much sensitive data, the security expectations on that platform are proportionally higher.
The trajectory Horizon3's fundraise describes, toward continuous validation rather than periodic snapshots, is the direction responsible software businesses are moving. The companies investing in that model are not doing it because regulators forced them to. They are doing it because the cost of a breach across an interconnected platform is genuinely high, and because customers running serious operations are starting to ask serious questions.
The Practical Takeaway
Horizon3 reaching a $2 billion valuation is not a story about venture capital. It is a signal that continuous security validation is becoming table stakes for cloud software, and that expectation is flowing downstream to every platform your business depends on.
As a contractor, the actionable move is not to become a security expert. It is to treat software security as part of your vendor evaluation process, the same way you evaluate financial stability, support quality, and integration depth. Ask your vendors the three questions above. Review your own data practices: who has admin access to your ops platform, are old employee accounts deactivated promptly, and are you using multi-factor authentication across your team.
The shift in the security industry that Horizon3 represents is ultimately about replacing invisible risk with visible, continuous operational discipline. That is a concept that will feel familiar to anyone who has ever managed a maintenance program on a large commercial account.
If you are thinking through what that kind of operational discipline looks like across your whole business, from how jobs are dispatched and billed to how your workforce data is managed, that is exactly the kind of conversation PolarPath is built around. Start with a walkthrough at polarpath.ca.

