NINA is the multi-agent AI engine behind the Zynap platform, and in July it went live for every Zynap customer.
Ask it about your attack surface, a threat actor, your leaked credentials or a malware sample and it answers in real time. Then tell it what needs fixing and it designs the workflow, shows you every step and waits for you to confirm before anything builds or runs.
Two months in, it’s time we told the whole story of what NINA does and why we built it.
TL;DR
- Live threat intelligence: ask what threatens you and get the answer from your own attack surface in real time.
- Contextual scoring: know which vulnerabilities to patch now, this week or this month.
- Automated action: NINA designs, builds and repairs workflows from a conversation, and nothing it starts runs until you confirm.
- Full-stack context: it works with the tools you already run, so there’s nothing to replace.
- Ready-to-use or fully custom agents: use ours or build your own on the models and tools you choose.
- Governed by design: you decide what runs on its own, and every action can be traced.
The Problem NINA Solves
Triaging an alert means pulling the threat actor’s profile, checking the indicator’s reputation and correlating it with your own exposure. Investigating an incident means tracing the kill chain from a hash or a domain, identifying the actor and mapping the techniques to MITRE ATT&CK.
With NINA, your team can investigate, build, troubleshoot and respond from a single conversation without leaving Zynap.
Mandiant’s M-Trends 2026 report tracked the handoff between the attacker who first breaks in and the group that runs attacks like ransomware. The median time fell from more than eight hours in 2022 to 22 seconds in 2025. That’s the pace we mean when we say machine speed.
The time a weakness stays open to an attacker is what we call the exposure window. In the first half of 2026, almost a quarter of the vulnerabilities VulnCheck confirmed as exploited were attacked on or before the day they were published. The part you control is how fast you close it. That’s the mobilize stage of Continuous Threat Exposure Management (CTEM), and it’s where Zynap acts. We proposed MTRER, short for Mean Time to Reduce Exploitable Risk, to measure it. Closing the window before anyone can use it is what we mean by preemptive.
How NINA Works
Behind every conversation, four specialist agents split the work between security knowledge, workflow design, troubleshooting and threat intelligence. NINA picks the right one for each question, so there’s nothing for you to set up.
It knows which part of the platform you’re working in, so a question asked from the attack surface view gets an answer about your attack surface. On security and platform questions, it shows the sources behind the answer and tells you when something comes from general knowledge.
What NINA Brings to Your Security Operations
Live Threat Intelligence
Ask NINA “What threatens us right now?” and it starts with your own internet-facing assets. It checks the vulnerabilities on them for active exploitation, exploit probability and severity. Then it links the ones that matter most to the threat actors associated with them.
You can also ask about attackers directly.
- “What do we know about APT29’s recent activity in the finance sector?”
- “How many threat actors target the finance sector? List them.”
- “Show me credential exposure for our domain and flag any spikes in the last six months.”
For malware, NINA can show you what the sandbox saw a sample do, ranked by severity, and which YARA rules it matched. Some of those rules name the malware family outright. Zynap customers can also use the Zynap Sandbox. It detonates suspicious files, maps their behavior to MITRE ATT&CK and feeds the indicators into the workflows you already run.
Those answers draw on intelligence we build ourselves. Zynap tracks more than 900 threat actors and campaigns and detects more than 600 million exposed credentials a month.
Contextual Scoring
Give NINA hundreds of CVEs and ask which to patch first. It scores each one on severity, exploit probability, active exploitation and links to known threat actors. The list comes back sorted into Patch Now, This Week, This Month and Monitor, and it flags known exploited vulnerabilities that are overdue.
Automated Action
Describe a job in a sentence and NINA designs the workflow. Ask for “a workflow that monitors new domains for our brand and alerts on phishing lookalikes” and it draws the design as a diagram in the chat. NINA builds with the real domain you name, so there are no placeholders to swap out. It can even design a full incident-response pipeline with enrichment, triage, approval and containment from a single message. It only uses steps and integrations that exist on the platform, and nothing gets built until you’ve seen the diagram and confirmed it.
When a workflow fails, ask NINA to diagnose it. It pulls up the whole run and works out where it broke and why. Once you confirm the diagnosis, it applies the fix, runs the workflow again and tells you whether the fix held.
Full-Stack Context
Zynap connects to the SIEM, EDR, identity, cloud, ticketing, firewall and email security tools you already run, so there’s nothing to rip out and replace. The workflows NINA builds act on your live environment through them. And because your threat intelligence, attack surface and credential exposure sit in one place, NINA can put the attacker’s side and yours in the same answer.
Ready-to-Use or Fully Custom Agents
Four ready-made agents work inside any workflow with no setup and no prompt engineering. They transform data, write and run scripts, summarize validated results and screen documents by context.
For anything more specific, you build a custom agent with your own instructions, tools, model and provider. It can reach a public service or your own infrastructure through MCP. It reads the data in front of it, picks a tool, runs it, checks the result and keeps going until the job is done. You can watch every step live in the Thought Process panel.
Each agent can run on its own model and hand work to the next. New models become available automatically, and NINA can add your agents as steps in the workflows it designs.
What It Means for MSSPs and In-House Teams
Every client keeps its own tenant, so a workflow you build once can run across your whole portfolio without one client’s data touching another’s. New clients come online from the use-case library in days, and the hours your analysts get back go into investigation and higher-value services.
For a team running security inside one organization, NINA shortens the path from finding a problem to fixing it. Gartner expects organizations that integrate exposure assessment data into their IT and business workflows to see 30% less unplanned downtime from exploited vulnerabilities by 2027.
How You Govern NINA
NINA’s agents act on your environment, so they work inside guardrails you set. Gartner describes the analyst’s role in autonomous cyber defense changing from operator to governor.² That’s the shift NINA is built for.
You Decide What Runs on Its Own
Nothing NINA starts from the chat runs until you confirm it, and workflows you schedule run on the schedule you set. In the workflows NINA designs, destructive actions like isolating a host, blocking an indicator or revoking credentials get an approval step in front of them. NINA warns you if one is missing.
Your Data Stays Yours
Every request is authenticated and scoped to your tenant, and NINA never sees another organization’s data. You also choose the AI model and provider each of your agents runs on.
Built to Resist Manipulation
Anyone can put text in a hostname, a page title or a certificate on your attack surface, so NINA reads that text only as data. It also checks attachments, workflow content and the results it pulls back for prompt-injection attempts. A workflow with a confirmed injection attempt is blocked from running.
Every Action Leaves a Record
Every automated action and every human decision can be traced afterward. NINA only reports a fix as successful when something changed, and it tells you when the data in front of it can’t support an answer. For teams working under NIS2, DORA or the EU AI Act, that record matters.
What’s New with NINA
We’ve kept shipping since July. Since late August, NINA assembles a large design from a single message. Its ceiling for a single design has gone up to 100 steps, and it now finds workflows and templates by what they do.
In September 2026, Zynap was recognized in Gartner’s Emerging Tech Impact Radar: Preemptive Cybersecurity as a Sample Vendor for Autonomous Cyber Defense System. Gartner describes that category as “an intelligent, agentic orchestration layer that unifies disconnected security controls and IT environments into a self-defending system.” The other eight vendors on that list are established companies. Gartner’s description is also a fair account of what we’ve been building.
If you’re already on Zynap, NINA is part of your platform today. If you’re not, we’d be glad to show you what it can do.
