Cobalt
Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs AI-powered offensive security automation with a vetted community of 500+ human pentesters (Cobalt Core). It delivers on-demand penetration testing, DAST, and attack surface management to 1,500+ enterprise, mid-market, and SMB customers via an annual credit-based subscription model.
- Company typePrivate
- Founded2013
- HeadquartersBoston, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Cobalt does
Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs a SaaS-based offensive security platform with a vetted community of human penetration testers (Cobalt Core). Founded in 2013 and headquartered in Boston with a fully remote workforce, Cobalt delivers on-demand penetration testing across web applications, APIs, mobile, AI/LLM systems, internal and external networks, cloud environments (AWS, Azure, GCP), and IoT ecosystems, complemented by secure code review, red teaming, digital risk assessment, attack surface management (ASM), and DAST (Dynamic Application Security Testing, powered by Snyk). The platform centralizes scoping, findings, remediation workflows, and benchmarking, with 50+ native integrations into developer, ticketing, communication, and compliance tools such as Jira, GitHub, Azure DevOps, Slack, ServiceNow, and Vanta. AI capabilities, including a Discovery Agent with Adversarial Toolchain, AI-Powered Scoping, AI Pentest Assistant, and AI-Powered Report Writer, are layered on top of more than a decade of proprietary exploit intelligence to automate reconnaissance, triage, and documentation while human pentesters validate findings.
Cobalt serves enterprise, mid-market, and SMB customers across software/SaaS, financial services, healthcare, telecommunications, education, and logistics, with named logos including Vonage, Dropbox, Credit Karma, Toast, Pendo, Algolia, Aircall, Egnyte, MuleSoft, Verifone, Flexport, Cengage, Gallagher, Quinyx, Insurity, CentralReach, Syndio, Progyny, Kubra, Jarvis Analytics, Personio, Snow Software, Talkdesk, Smarsh, Sentara Healthcare, Fresenius Kabi, Movingimage, and Institutional Shareholder Services. The go-to-market is sales-led with quote-based pricing: customers purchase annual "Cobalt Credits" packages (each credit equals 8 hours of offensive security testing) across Standard, Premium, and Pool tiers, with named CSMs and free retesting included at higher tiers. The platform also supports self-service for existing accounts and integration-driven distribution via deep Vanta compliance integration.
Cobalt's revenue model combines recurring annual subscriptions (Cobalt Credits), usage-based consumption (mid-year top-ups, up to 10% credit rollover on Pool tier), and professional pentesting services delivered by the Cobalt Core community. The company has reported over 1,500 customers, 5,000+ pentests annually, 31,000+ testing days and approximately 255,000 hours of pentesting delivered in 2025, and a 7%+ customer base growth rate in 2025. Cobalt has raised approximately $37M in disclosed funding, led by a $29M Series B in 2020 from Highland Europe, with no disclosed revenue figure.
Cobalt firmographics
Firmographics- Name
- Cobalt
- Legal name
- Cobalt
- Website
- https://cobalt.io
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs AI-powered offensive security automation with a vetted community of 500+ human pentesters (Cobalt Core). It delivers on-demand penetration testing, DAST, and attack surface management to 1,500+ enterprise, mid-market, and SMB customers via an annual credit-based subscription model.
- Ownership category
- akta.pro rank
Cobalt industry classification
Industry- Product category
- Penetration Testing as a Service (PTaaS)
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing Platforms (PTaaS) (HDADAHAG)
- akta.pro secondary industries
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC), Penetration Testing & Red Teaming (BPAKAHAF), Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK)
Keywords
Where Cobalt is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
Cobalt business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cobalt Credits (Annual Subscription Packages): Annual credit packages sold on a subscription/recurring basis. A Cobalt Credit represents 8 hours of offensive security testing delivered via AI plus human expertise. Packages include asset scoping, testing, retesting, platform access, and reporting. Tiers include Standard, Premium, and Pool with named CSMs, SAML SSO, DAST targets, and varying onboarding levels.
- Usage-Based Pentest Delivery: Customers consume credits on demand for pentests, retesting, DAST scans, ASM, and advanced services. Mid-year top-ups are available if attack surface grows, and up to 10% credit rollover is offered in higher tiers.
- Professional Pentesting Services: Manual penetration testing services (web, mobile, API, AI/LLM, network, cloud, red teaming) and ancillary services (secure code review, digital risk assessment, IoT testing, security program manager) delivered by the Cobalt Core community.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Standard - for teams needing a speedy annual pentest to meet compliance or client requests |
| Subscription | Annual | Premium - for teams building a structured pentest program to meet compliance and improve security |
| Subscription | Annual | Pool - for teams scaling pentest programs with increased frequency and depth |
| Unit Pricing | Annual | Cobalt Credits (unit pricing) - 8 hours of offensive security testing per credit |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels9 records
Cobalt product offering
Product offeringCore offering
Cobalt is a Pentest-as-a-Service (PTaaS) platform that combines a SaaS-based offensive security platform with a vetted human pentester community (Cobalt Core of 500+ testers) to deliver on-demand penetration testing, attack surface monitoring, dynamic application security testing (DAST), secure code review, cloud and network pentests, and red teaming. Customers buy annual Cobalt Credit packages (each credit equals 8 hours of offensive security testing) and consume them across web, API, mobile, AI/LLM, cloud, and network engagements, with AI-powered automation layered on top of a decade of proprietary exploit intelligence.
Product overview
Cobalt offers a unified offensive security platform-plus-services architecture anchored by the Cobalt Platform (the core PTaaS solution) and the Cobalt Core (its vetted pentester community). The platform combines manual human testing with AI-powered automation (Human-Led, AI-Powered Pentesting) and integrates with 50+ developer, ticketing, compliance, and communication tools. Built-in product modules include Attack Surface Management (ASM) for continuous external monitoring, Cobalt DAST (powered by Snyk) for automated web/API vulnerability scanning, and a public Cobalt API for workflow integration. The platform delivers a portfolio of specialized services: Web Application, API, Mobile, AI & LLM, and Secure Code Review (under Application Security); Internal and External Network Pentests (under Network Security); Cloud Pentest and Cloud Configuration Review (under Cloud Security); plus Red Teaming, Digital Risk Assessment, IoT Ecosystem Pentest, and Security Program Manager services. ASM and DAST operate as continuous scanning modules that complement the discrete pentest engagements.
Differentiator
Problem solved
Functional benefit
Brands
- Cobalt Core: Community of vetted penetration testing experts delivering services through the Cobalt PTaaS platform.
- Cobalt Platform
- Cobalt DAST
- Cobalt Credits
Products and services
- Cobalt Platform (Offensive Security Platform) SaaS-based offensive security platform that orchestrates PTaaS engagements, centralizes pentest findings, and supports remediation workflows across an organization's attack surface.
- Pentest as a Service (PTaaS) On-demand penetration testing as a service platform that combines manual human testing with modern delivery workflows, integrations, easy reporting, and credit-based consumption. Customers can start a pentest in as little as 24 hours.
- Web Application Pentest Expert-led penetration testing of web applications aligned to OWASP standards and modern DevSecOps workflows, identifying vulnerabilities that matter for web properties.
- API Pentest OWASP-aligned penetration testing for APIs including RESTful, GraphQL, and SOAP, focused on authentication, data exchange, and access controls.
- AI & LLM Pentest Specialized penetration testing for AI and LLM-integrated systems addressing prompt injection, model denial of service, jailbreak, and other LLM-specific threats; pentesters contribute to OWASP Top 10 for LLM applications.
- Mobile Pentest Penetration testing of iOS and Android mobile applications to identify platform-specific vulnerabilities.
- Secure Code Review Human-led analysis of source code combining SAST and SCA automated scanning with manual review to identify and mitigate security vulnerabilities throughout the SDLC, using OWASP-driven methodology.
- Internal Network Pentest OSSTMM-aligned penetration testing of internal network infrastructure to identify misconfigurations, weak permissions, Active Directory vulnerabilities, and validate network segmentation against insider threats.
- External Network Pentest Penetration testing of public-facing systems including web, FTP, email, and DNS servers, firewalls, and routers, aligned to OSSTMM standards.
- Cloud Pentest Service Multi-cloud and hybrid penetration testing for AWS, Azure, and GCP environments, aligned to OWASP Cloud-Native Top 10 and the Shared Responsibility Model, testing IAM, storage, networking, and compute.
- Cloud Configuration Review Expert review of cloud service configurations across AWS, Azure, and GCP to validate security controls and identify misconfigurations, with focus on container hardening and authentication.
- Attack Surface Management (ASM) Automated, continuous monitoring of external attack surface including daily scans for new hosts, port changes, IP modifications, and identification of shadow IT assets, missing security headers, and weak ciphers.
- Cobalt DAST (Dynamic Application Security Testing) Automated continuous vulnerability scanning of web applications and APIs powered by Snyk technology, detecting over 30,000 potential vulnerabilities with authenticated scans, detailed remediation guidance, and integrated pentesting workflow; integrates with 100+ tools via the Cobalt API.
- Red Teaming Adversary simulation engagements that replicate movements of a motivated attacker to identify critical risks and test defenses against real-world attack scenarios.
- Digital Risk Assessment Comprehensive assessment of digital risks beyond technical vulnerabilities, supporting brand protection and external threat landscape evaluation.
- IoT Ecosystem Pentest Penetration testing of IoT ecosystems covering devices, firmware, communications, and supporting infrastructure.
- Security Program Manager Strategic advisory service supporting offensive security program execution, including planning, scope management, and coordination across multiple engagements.
Quantifiable outcome
- 2.6X faster time to report than traditional pentesting
- +14 more outcomes
Companies that use Cobalt
Customer profileNamed customers31 records
Segments8 records
Ideal customer profiles4 records
Cobalt technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration15 records
AI capability11 records
Feature10 records
Cobalt partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered strategic and core.
- VantastrategicDeep integration with Vanta's trust management platform. Cobalt syncs users, assets, and findings data with Vanta, automating evidence collection for 35 tests and 11 controls. Joint customers can ensure vulnerabilities identified through Cobalt's pentesting are automatically tracked and managed within Vanta's compliance framework.
- SnykstrategicSnyk technology powers Cobalt's DAST (Dynamic Application Security Testing) engine. Cobalt DAST is branded 'powered by Snyk' on the platform page. The DAST solution detects over 30,000 potential vulnerabilities across web applications and APIs and integrates with 100+ tools via the Cobalt API.
- Atlassian (Jira)coreNative integration to push Cobalt pentest findings as issues into Jira Cloud/Server, streamlining remediation workflows for engineering teams.
- GitHubcoreNative integration enables two-way syncing of pentest findings with GitHub issues, embedding security findings directly into developer workflows.
- GitLabcoreNative integration to create GitLab tickets directly from Cobalt findings.
- Microsoft (Azure DevOps / Microsoft Teams)coreNative integrations to push findings as work items to Azure DevOps Boards and to enable real-time pentester collaboration in Microsoft Teams (share screenshots and proof of exploits).
- Slack (Salesforce)coreNative Slack integration for real-time collaboration between customers and Cobalt pentesters, plus automated notifications for findings.
- ServiceNowcoreNative integration to push Cobalt findings as incidents to ServiceNow for enterprise ITSM workflows.
Scale indicators16 records
Recent moves6 records
Expansion highlights6 records
Cobalt competitors and assessment
Company assessmentDirect peers
- Bugcrowd: Bugcrowd operates a crowdsourced security platform spanning bug bounty, PTaaS, and vulnerability disclosure. Comparable to Cobalt in serving enterprise customers with on-demand offensive security via a researcher community, with overlapping GTM and product capabilities.
- NetSPI: NetSPI is a penetration testing services and PTaaS platform with a strong enterprise customer base and a vetted security consultant model. Direct overlap with Cobalt on web/app/network/cloud pentest offerings, compliance testing, and mid-market/enterprise buyers.
- Bishop Fox: Bishop Fox is a traditional offensive security consultancy that has expanded into platform-based continuous testing. Comparable to Cobalt on enterprise pentest services (web, network, cloud, red team) and on the shift toward software-delivered offensive security programs.
- Synack: Synack is a direct PTaaS competitor offering on-demand penetration testing through a vetted security researcher community combined with AI/automation. Closely aligned with Cobalt on delivery model (crowd of vetted testers), customer base (enterprise), and platform capabilities (scoping, integrations, reporting).
- HackerOne: HackerOne is the leading bug bounty and PTaaS platform, combining a global hacker community with continuous security testing. Direct overlap with Cobalt on PTaaS delivery model, enterprise buyer, and crowd-based offensive security, though HackerOne's hacker community model is broader than Cobalt's vetted Core.
Emerging players
- Pentera: Pentera offers automated security validation that emulates attacker techniques against enterprise networks. Adjacent competitor to Cobalt in offensive security, overlapping on enterprise buyers and continuous validation use cases, but emphasizing fully automated attack simulation rather than human pentesters.
- Horizon3.ai: Horizon3.ai provides autonomous penetration testing with its NodeZero platform, targeting the same enterprise security buyer as Cobalt. An AI-native emerging player that competes with Cobalt's ASM and continuous testing offerings, though with a fully automated rather than human-led model.
Others
- Snyk: Snyk is both a strategic technology partner (powers Cobalt DAST) and an adjacent competitor in developer security. Their overlapping application security, SAST, and DAST offerings mean Snyk could expand into PTaaS-adjacent capabilities, creating both opportunity and threat for Cobalt.
Broad incumbents
- CrowdStrike: CrowdStrike is a broad endpoint and cloud security incumbent with growing offensive security and exposure management capabilities. Overlaps with Cobalt on enterprise buyers, attack surface monitoring, and the trend toward integrated security testing, though CrowdStrike does not specialize in PTaaS.
- Trustwave: Trustwave is a managed security services provider offering penetration testing alongside MDR and consulting. Competes with Cobalt on enterprise pentest services, compliance testing, and the broader offensive security budget, while bringing a wider services portfolio.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key highlights7 records
Customer concentration
Cobalt social profiles
Digital presenceCobalt financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cobalt leadership team
Management profileNumber of profiles
Profiles15 records
Cobalt subsidiaries and ownership
Company hierarchySubsidiaries1 record
Cobalt funding detail
Funding detailFunding overview
Funding rounds8 records
Investors12 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cobalt M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cobalt
What does Cobalt do?
Cobalt is a Pentest-as-a-Service (PTaaS) platform that combines a SaaS-based offensive security platform with a vetted human pentester community (Cobalt Core of 500+ testers) to deliver on-demand penetration testing, attack surface monitoring, dynamic application security testing (DAST), secure code review, cloud and network pentests, and red teaming. Customers buy annual Cobalt Credit packages (each credit equals 8 hours of offensive security testing) and consume them across web, API, mobile, AI/LLM, cloud, and network engagements, with AI-powered automation layered on top of a decade of proprietary exploit intelligence.
Is Cobalt a public or private company?
Cobalt is a private company. It is classified as venture growth investor backed and is currently operating.
When was Cobalt founded?
Cobalt was founded in 2013. It employs 1 to 10 people.
Where is Cobalt based?
Cobalt is headquartered in Boston, United States, in the North America region.
How does Cobalt make money?
Three revenue lines are on record. Cobalt Credits (Annual Subscription Packages) is the primary driver. The others are usage-Based Pentest Delivery and professional Pentesting Services.
Who are Cobalt's main competitors?
Direct peers on record are Bugcrowd, NetSPI, Bishop Fox, Synack and HackerOne. Emerging players are Pentera and Horizon3.ai. Snyk is listed as an others. Broad incumbents are CrowdStrike and Trustwave.
Does Cobalt have an API?
Yes. Cobalt offers a public API (REST-based) that allows customers to programmatically relay pentest findings to their development workflows and integrate Cobalt's offensive security data into their existing systems. Available to platform users with documentation at docs.cobalt.io/cobalt-api/. The platform is described as "MCP Compatible" for AI integrations. Developer documentation is at docs.cobalt.io/cobalt-api.
What industry is Cobalt in?
Cobalt's product category is Penetration Testing as a Service (PTaaS). Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS), with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 561621 and its SIC code is 8734.