Developer docs
API playgroundTry for free, no card

Search company profiles

Cobalt

Full company profile

uuid00005p9

Namestring
Cobalt
Legal namestring
Cobalt
Websiteurl
cobalt.io
Company typeenum
Private
Founded yearint
2013
Descriptiontext

Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs a SaaS-based offensive security platform with a vetted community of human penetration testers (Cobalt Core). Founded in 2013 and headquartered in Boston with a fully remote workforce, Cobalt delivers on-demand penetration testing across web applications, APIs, mobile, AI/LLM systems, internal and external networks, cloud environments (AWS, Azure, GCP), and IoT ecosystems, complemented by secure code review, red teaming, digital risk assessment, attack surface management (ASM), and DAST (Dynamic Application Security Testing, powered by Snyk). The platform centralizes scoping, findings, remediation workflows, and benchmarking, with 50+ native integrations into developer, ticketing, communication, and compliance tools such as Jira, GitHub, Azure DevOps, Slack, ServiceNow, and Vanta. AI capabilities, including a Discovery Agent with Adversarial Toolchain, AI-Powered Scoping, AI Pentest Assistant, and AI-Powered Report Writer, are layered on top of more than a decade of proprietary exploit intelligence to automate reconnaissance, triage, and documentation while human pentesters validate findings.

Cobalt serves enterprise, mid-market, and SMB customers across software/SaaS, financial services, healthcare, telecommunications, education, and logistics, with named logos including Vonage, Dropbox, Credit Karma, Toast, Pendo, Algolia, Aircall, Egnyte, MuleSoft, Verifone, Flexport, Cengage, Gallagher, Quinyx, Insurity, CentralReach, Syndio, Progyny, Kubra, Jarvis Analytics, Personio, Snow Software, Talkdesk, Smarsh, Sentara Healthcare, Fresenius Kabi, Movingimage, and Institutional Shareholder Services. The go-to-market is sales-led with quote-based pricing: customers purchase annual "Cobalt Credits" packages (each credit equals 8 hours of offensive security testing) across Standard, Premium, and Pool tiers, with named CSMs and free retesting included at higher tiers. The platform also supports self-service for existing accounts and integration-driven distribution via deep Vanta compliance integration.

Cobalt's revenue model combines recurring annual subscriptions (Cobalt Credits), usage-based consumption (mid-year top-ups, up to 10% credit rollover on Pool tier), and professional pentesting services delivered by the Cobalt Core community. The company has reported over 1,500 customers, 5,000+ pentests annually, 31,000+ testing days and approximately 255,000 hours of pentesting delivered in 2025, and a 7%+ customer base growth rate in 2025. Cobalt has raised approximately $37M in disclosed funding, led by a $29M Series B in 2020 from Highland Europe, with no disclosed revenue figure.

Short descriptiontext

Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs AI-powered offensive security automation with a vetted community of 500+ human pentesters (Cobalt Core). It delivers on-demand penetration testing, DAST, and attack surface management to 1,500+ enterprise, mid-market, and SMB customers via an annual credit-based subscription model.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersBoston, United States
HQ citystring
Boston
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices4 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
penetration testing services, offensive security platform, Pentest as a Service, attack surface management, dynamic application security testing
Industry4 codes
1Penetration Testing Platforms (PTaaS)
CodeHDADAHAGPrimaryYes
2Application Security Testing (SAST/DAST/IAST/SCA)
CodeHDADACACPrimaryNo
3Penetration Testing & Red Teaming
CodeBPAKAHAFPrimaryNo
4Security Testing Tooling (SAST/DAST for smart contracts, fuzzing)
CodeFSAPAJAKPrimaryNo
NAICS code1 code
  • Security Systems Services (except Locksmiths)561621
SIC code1 code
  • Services-Testing Laboratories8734
Product category
Penetration Testing as a Service (PTaaS)
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model3 records
1Cobalt Credits (Annual Subscription Packages)
TypeSubscription Recurring
Description

Annual credit packages sold on a subscription/recurring basis. A Cobalt Credit represents 8 hours of offensive security testing delivered via AI plus human expertise. Packages include asset scoping, testing, retesting, platform access, and reporting. Tiers include Standard, Premium, and Pool with named CSMs, SAML SSO, DAST targets, and varying onboarding levels.

cobalt.io
2Usage-Based Pentest Delivery
TypeUsage Based
Description

Customers consume credits on demand for pentests, retesting, DAST scans, ASM, and advanced services. Mid-year top-ups are available if attack surface grows, and up to 10% credit rollover is offered in higher tiers.

cobalt.io
3Professional Pentesting Services
TypeProfessional Services
Description

Manual penetration testing services (web, mobile, API, AI/LLM, network, cloud, red teaming) and ancillary services (secure code review, digital risk assessment, IoT testing, security program manager) delivered by the Cobalt Core community.

cobalt.io
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Pricing details4 tiers
1Standard - for teams needing a speedy annual pentest to meet compliance or client requests
ModelSubscriptionBilling cadenceAnnual
Notes

Pool onboarding via email; 1 DAST target included; 3 business days to start; 6 months free retesting; includes SAML-based SSO, ASM, native integrations, customizable reports

cobalt.io
2Premium - for teams building a structured pentest program to meet compliance and improve security
ModelSubscriptionBilling cadenceAnnual
Notes

Live onboarding support; 2 business days to start; 12 months free retesting; includes all Standard features plus additional platform capabilities

cobalt.io
3Pool - for teams scaling pentest programs with increased frequency and depth
ModelSubscriptionBilling cadenceAnnual
Notes

Named CSM; 1 business day to start; 12 months free retesting; strategic program planning; quarterly business reviews; up to 10% credit rollover; custom pentester requests by geo/timezone/window

cobalt.io
4Cobalt Credits (unit pricing) - 8 hours of offensive security testing per credit
ModelUnit PricingBilling cadenceAnnual
Notes

Credits sold in annual packages that include asset scoping, testing, retesting, platform access, and reporting. Mid-year top-ups available. Up to 10% credit rollover available on Pool tier.

cobalt.io
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 4 records shown
1Cobalt Core
Description

Community of vetted penetration testing experts delivering services through the Cobalt PTaaS platform.

cobalt.io
+3 more records
Core offering1 text field

Cobalt is a Pentest-as-a-Service (PTaaS) platform that combines a SaaS-based offensive security platform with a vetted human pentester community (Cobalt Core of 500+ testers) to deliver on-demand penetration testing, attack surface monitoring, dynamic application security testing (DAST), secure code review, cloud and network pentests, and red teaming. Customers buy annual Cobalt Credit packages (each credit equals 8 hours of offensive security testing) and consume them across web, API, mobile, AI/LLM, cloud, and network engagements, with AI-powered automation layered on top of a decade of proprietary exploit intelligence.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 15 values shown
  • 2.6X faster time to report than traditional pentesting
+14 more records
Product overview1 text field

Cobalt offers a unified offensive security platform-plus-services architecture anchored by the Cobalt Platform (the core PTaaS solution) and the Cobalt Core (its vetted pentester community). The platform combines manual human testing with AI-powered automation (Human-Led, AI-Powered Pentesting) and integrates with 50+ developer, ticketing, compliance, and communication tools. Built-in product modules include Attack Surface Management (ASM) for continuous external monitoring, Cobalt DAST (powered by Snyk) for automated web/API vulnerability scanning, and a public Cobalt API for workflow integration. The platform delivers a portfolio of specialized services: Web Application, API, Mobile, AI & LLM, and Secure Code Review (under Application Security); Internal and External Network Pentests (under Network Security); Cloud Pentest and Cloud Configuration Review (under Cloud Security); plus Red Teaming, Digital Risk Assessment, IoT Ecosystem Pentest, and Security Program Manager services. ASM and DAST operate as continuous scanning modules that complement the discrete pentest engagements.

Product and service17 records
1Cobalt Platform (Offensive Security Platform)
CategoryOffensive Security Platform
Description

SaaS-based offensive security platform that orchestrates PTaaS engagements, centralizes pentest findings, and supports remediation workflows across an organization's attack surface.

2Pentest as a Service (PTaaS)
CategoryPenetration Testing Service
Description

On-demand penetration testing as a service platform that combines manual human testing with modern delivery workflows, integrations, easy reporting, and credit-based consumption. Customers can start a pentest in as little as 24 hours.

3Web Application Pentest
CategoryApplication Security Service
Description

Expert-led penetration testing of web applications aligned to OWASP standards and modern DevSecOps workflows, identifying vulnerabilities that matter for web properties.

4API Pentest
CategoryApplication Security Service
Description

OWASP-aligned penetration testing for APIs including RESTful, GraphQL, and SOAP, focused on authentication, data exchange, and access controls.

5AI & LLM Pentest
CategoryApplication Security Service
Description

Specialized penetration testing for AI and LLM-integrated systems addressing prompt injection, model denial of service, jailbreak, and other LLM-specific threats; pentesters contribute to OWASP Top 10 for LLM applications.

6Mobile Pentest
CategoryApplication Security Service
Description

Penetration testing of iOS and Android mobile applications to identify platform-specific vulnerabilities.

7Secure Code Review
CategoryApplication Security Service
Description

Human-led analysis of source code combining SAST and SCA automated scanning with manual review to identify and mitigate security vulnerabilities throughout the SDLC, using OWASP-driven methodology.

8Internal Network Pentest
CategoryNetwork Security Service
Description

OSSTMM-aligned penetration testing of internal network infrastructure to identify misconfigurations, weak permissions, Active Directory vulnerabilities, and validate network segmentation against insider threats.

9External Network Pentest
CategoryNetwork Security Service
Description

Penetration testing of public-facing systems including web, FTP, email, and DNS servers, firewalls, and routers, aligned to OSSTMM standards.

10Cloud Pentest Service
CategoryCloud Security Service
Description

Multi-cloud and hybrid penetration testing for AWS, Azure, and GCP environments, aligned to OWASP Cloud-Native Top 10 and the Shared Responsibility Model, testing IAM, storage, networking, and compute.

11Cloud Configuration Review
CategoryCloud Security Service
Description

Expert review of cloud service configurations across AWS, Azure, and GCP to validate security controls and identify misconfigurations, with focus on container hardening and authentication.

12Attack Surface Management (ASM)
CategorySecurity Monitoring Module
Description

Automated, continuous monitoring of external attack surface including daily scans for new hosts, port changes, IP modifications, and identification of shadow IT assets, missing security headers, and weak ciphers.

13Cobalt DAST (Dynamic Application Security Testing)
CategoryAutomated Security Scanning
Description

Automated continuous vulnerability scanning of web applications and APIs powered by Snyk technology, detecting over 30,000 potential vulnerabilities with authenticated scans, detailed remediation guidance, and integrated pentesting workflow; integrates with 100+ tools via the Cobalt API.

14Red Teaming
CategoryOffensive Security Service
Description

Adversary simulation engagements that replicate movements of a motivated attacker to identify critical risks and test defenses against real-world attack scenarios.

15Digital Risk Assessment
CategoryBrand Protection Service
Description

Comprehensive assessment of digital risks beyond technical vulnerabilities, supporting brand protection and external threat landscape evaluation.

16IoT Ecosystem Pentest
CategorySpecialty Security Service
Description

Penetration testing of IoT ecosystems covering devices, firmware, communications, and supporting infrastructure.

17Security Program Manager
CategoryAdvisory Service
Description

Strategic advisory service supporting offensive security program execution, including planning, scope management, and coordination across multiple engagements.

Scale indicator16 records

Each record includes

Type, Value, Description, Source

Partnership8 partners
Strategic tierStrategicTypeTechnology or Integration
Description

Deep integration with Vanta's trust management platform. Cobalt syncs users, assets, and findings data with Vanta, automating evidence collection for 35 tests and 11 controls. Joint customers can ensure vulnerabilities identified through Cobalt's pentesting are automatically tracked and managed within Vanta's compliance framework.

Strategic tierStrategicTypeTechnology or Integration
Description

Snyk technology powers Cobalt's DAST (Dynamic Application Security Testing) engine. Cobalt DAST is branded 'powered by Snyk' on the platform page. The DAST solution detects over 30,000 potential vulnerabilities across web applications and APIs and integrates with 100+ tools via the Cobalt API.

Strategic tierCoreTypeTechnology or Integration
Description

Native integration to push Cobalt pentest findings as issues into Jira Cloud/Server, streamlining remediation workflows for engineering teams.

Strategic tierCoreTypeTechnology or Integration
Description

Native integration enables two-way syncing of pentest findings with GitHub issues, embedding security findings directly into developer workflows.

Strategic tierCoreTypeTechnology or Integration
Description

Native integration to create GitLab tickets directly from Cobalt findings.

Strategic tierCoreTypeTechnology or Integration
Description

Native integrations to push findings as work items to Azure DevOps Boards and to enable real-time pentester collaboration in Microsoft Teams (share screenshots and proof of exploits).

Strategic tierCoreTypeTechnology or Integration
Description

Native Slack integration for real-time collaboration between customers and Cobalt pentesters, plus automated notifications for findings.

Strategic tierCoreTypeTechnology or Integration
Description

Native integration to push Cobalt findings as incidents to ServiceNow for enterprise ITSM workflows.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Bugcrowd operates a crowdsourced security platform spanning bug bounty, PTaaS, and vulnerability disclosure. Comparable to Cobalt in serving enterprise customers with on-demand offensive security via a researcher community, with overlapping GTM and product capabilities.

TypeDirect peer
Description

NetSPI is a penetration testing services and PTaaS platform with a strong enterprise customer base and a vetted security consultant model. Direct overlap with Cobalt on web/app/network/cloud pentest offerings, compliance testing, and mid-market/enterprise buyers.

TypeEmerging player
Description

Pentera offers automated security validation that emulates attacker techniques against enterprise networks. Adjacent competitor to Cobalt in offensive security, overlapping on enterprise buyers and continuous validation use cases, but emphasizing fully automated attack simulation rather than human pentesters.

TypeEmerging player
Description

Horizon3.ai provides autonomous penetration testing with its NodeZero platform, targeting the same enterprise security buyer as Cobalt. An AI-native emerging player that competes with Cobalt's ASM and continuous testing offerings, though with a fully automated rather than human-led model.

TypeDirect peer
Description

Bishop Fox is a traditional offensive security consultancy that has expanded into platform-based continuous testing. Comparable to Cobalt on enterprise pentest services (web, network, cloud, red team) and on the shift toward software-delivered offensive security programs.

TypeOthers
Description

Snyk is both a strategic technology partner (powers Cobalt DAST) and an adjacent competitor in developer security. Their overlapping application security, SAST, and DAST offerings mean Snyk could expand into PTaaS-adjacent capabilities, creating both opportunity and threat for Cobalt.

TypeBroad incumbent
Description

CrowdStrike is a broad endpoint and cloud security incumbent with growing offensive security and exposure management capabilities. Overlaps with Cobalt on enterprise buyers, attack surface monitoring, and the trend toward integrated security testing, though CrowdStrike does not specialize in PTaaS.

TypeBroad incumbent
Description

Trustwave is a managed security services provider offering penetration testing alongside MDR and consulting. Competes with Cobalt on enterprise pentest services, compliance testing, and the broader offensive security budget, while bringing a wider services portfolio.

TypeDirect peer
Description

Synack is a direct PTaaS competitor offering on-demand penetration testing through a vetted security researcher community combined with AI/automation. Closely aligned with Cobalt on delivery model (crowd of vetted testers), customer base (enterprise), and platform capabilities (scoping, integrations, reporting).

TypeDirect peer
Description

HackerOne is the leading bug bounty and PTaaS platform, combining a global hacker community with continuous security testing. Direct overlap with Cobalt on PTaaS delivery model, enterprise buyer, and crowd-based offensive security, though HackerOne's hacker community model is broader than Cobalt's vetted Core.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers31 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment8 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration15 records

Each record includes

Title, Type, Description, Source

AI capability11 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles15 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries1 record

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds8 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors12 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Cobalt

Penetration Testing as a Service (PTaaS)cobalt.io

Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs AI-powered offensive security automation with a vetted community of 500+ human pentesters (Cobalt Core). It delivers on-demand penetration testing, DAST, and attack surface management to 1,500+ enterprise, mid-market, and SMB customers via an annual credit-based subscription model.

What Cobalt does

Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs a SaaS-based offensive security platform with a vetted community of human penetration testers (Cobalt Core). Founded in 2013 and headquartered in Boston with a fully remote workforce, Cobalt delivers on-demand penetration testing across web applications, APIs, mobile, AI/LLM systems, internal and external networks, cloud environments (AWS, Azure, GCP), and IoT ecosystems, complemented by secure code review, red teaming, digital risk assessment, attack surface management (ASM), and DAST (Dynamic Application Security Testing, powered by Snyk). The platform centralizes scoping, findings, remediation workflows, and benchmarking, with 50+ native integrations into developer, ticketing, communication, and compliance tools such as Jira, GitHub, Azure DevOps, Slack, ServiceNow, and Vanta. AI capabilities, including a Discovery Agent with Adversarial Toolchain, AI-Powered Scoping, AI Pentest Assistant, and AI-Powered Report Writer, are layered on top of more than a decade of proprietary exploit intelligence to automate reconnaissance, triage, and documentation while human pentesters validate findings.

Cobalt serves enterprise, mid-market, and SMB customers across software/SaaS, financial services, healthcare, telecommunications, education, and logistics, with named logos including Vonage, Dropbox, Credit Karma, Toast, Pendo, Algolia, Aircall, Egnyte, MuleSoft, Verifone, Flexport, Cengage, Gallagher, Quinyx, Insurity, CentralReach, Syndio, Progyny, Kubra, Jarvis Analytics, Personio, Snow Software, Talkdesk, Smarsh, Sentara Healthcare, Fresenius Kabi, Movingimage, and Institutional Shareholder Services. The go-to-market is sales-led with quote-based pricing: customers purchase annual "Cobalt Credits" packages (each credit equals 8 hours of offensive security testing) across Standard, Premium, and Pool tiers, with named CSMs and free retesting included at higher tiers. The platform also supports self-service for existing accounts and integration-driven distribution via deep Vanta compliance integration.

Cobalt's revenue model combines recurring annual subscriptions (Cobalt Credits), usage-based consumption (mid-year top-ups, up to 10% credit rollover on Pool tier), and professional pentesting services delivered by the Cobalt Core community. The company has reported over 1,500 customers, 5,000+ pentests annually, 31,000+ testing days and approximately 255,000 hours of pentesting delivered in 2025, and a 7%+ customer base growth rate in 2025. Cobalt has raised approximately $37M in disclosed funding, led by a $29M Series B in 2020 from Highland Europe, with no disclosed revenue figure.

Cobalt firmographics

Firmographics
Name
Cobalt
Legal name
Cobalt
Website
https://cobalt.io
Company type
Private
Founded year
2013
Operating status
Operating
Headcount range
1–10 employees
Short description
Cobalt operates a Pentest-as-a-Service (PTaaS) platform that pairs AI-powered offensive security automation with a vetted community of 500+ human pentesters (Cobalt Core). It delivers on-demand penetration testing, DAST, and attack surface management to 1,500+ enterprise, mid-market, and SMB customers via an annual credit-based subscription model.
Ownership category
akta.pro rank

Cobalt industry classification

Industry
Product category
Penetration Testing as a Service (PTaaS)
NAICS
Security Systems Services (except Locksmiths) (561621)
SIC
Services-Testing Laboratories (8734)
akta.pro primary industry
Penetration Testing Platforms (PTaaS) (HDADAHAG)
akta.pro secondary industries
Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC), Penetration Testing & Red Teaming (BPAKAHAF), Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK)

Keywords

  • Penetration testing services
  • Offensive security platform
  • Pentest as a Service
  • Attack surface management
  • Dynamic application security testing

Where Cobalt is headquartered

Location

Headquarters

HQ city
Boston
HQ country
United States
HQ region
North America

Offices4 records

Markets served

Cobalt business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure

Revenue model

  1. Cobalt Credits (Annual Subscription Packages): Annual credit packages sold on a subscription/recurring basis. A Cobalt Credit represents 8 hours of offensive security testing delivered via AI plus human expertise. Packages include asset scoping, testing, retesting, platform access, and reporting. Tiers include Standard, Premium, and Pool with named CSMs, SAML SSO, DAST targets, and varying onboarding levels.
  2. Usage-Based Pentest Delivery: Customers consume credits on demand for pentests, retesting, DAST scans, ASM, and advanced services. Mid-year top-ups are available if attack surface grows, and up to 10% credit rollover is offered in higher tiers.
  3. Professional Pentesting Services: Manual penetration testing services (web, mobile, API, AI/LLM, network, cloud, red teaming) and ancillary services (secure code review, digital risk assessment, IoT testing, security program manager) delivered by the Cobalt Core community.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualStandard - for teams needing a speedy annual pentest to meet compliance or client requests
SubscriptionAnnualPremium - for teams building a structured pentest program to meet compliance and improve security
SubscriptionAnnualPool - for teams scaling pentest programs with increased frequency and depth
Unit PricingAnnualCobalt Credits (unit pricing) - 8 hours of offensive security testing per credit

Go-to-market motion1 record

Distribution channels4 records

Marketing channels9 records

Cobalt product offering

Product offering

Core offering

Cobalt is a Pentest-as-a-Service (PTaaS) platform that combines a SaaS-based offensive security platform with a vetted human pentester community (Cobalt Core of 500+ testers) to deliver on-demand penetration testing, attack surface monitoring, dynamic application security testing (DAST), secure code review, cloud and network pentests, and red teaming. Customers buy annual Cobalt Credit packages (each credit equals 8 hours of offensive security testing) and consume them across web, API, mobile, AI/LLM, cloud, and network engagements, with AI-powered automation layered on top of a decade of proprietary exploit intelligence.

Product overview

Cobalt offers a unified offensive security platform-plus-services architecture anchored by the Cobalt Platform (the core PTaaS solution) and the Cobalt Core (its vetted pentester community). The platform combines manual human testing with AI-powered automation (Human-Led, AI-Powered Pentesting) and integrates with 50+ developer, ticketing, compliance, and communication tools. Built-in product modules include Attack Surface Management (ASM) for continuous external monitoring, Cobalt DAST (powered by Snyk) for automated web/API vulnerability scanning, and a public Cobalt API for workflow integration. The platform delivers a portfolio of specialized services: Web Application, API, Mobile, AI & LLM, and Secure Code Review (under Application Security); Internal and External Network Pentests (under Network Security); Cloud Pentest and Cloud Configuration Review (under Cloud Security); plus Red Teaming, Digital Risk Assessment, IoT Ecosystem Pentest, and Security Program Manager services. ASM and DAST operate as continuous scanning modules that complement the discrete pentest engagements.

Differentiator

Problem solved

Functional benefit

Brands

  • Cobalt Core: Community of vetted penetration testing experts delivering services through the Cobalt PTaaS platform.
  • Cobalt Platform
  • Cobalt DAST
  • Cobalt Credits

Products and services

  • Cobalt Platform (Offensive Security Platform) SaaS-based offensive security platform that orchestrates PTaaS engagements, centralizes pentest findings, and supports remediation workflows across an organization's attack surface.
  • Pentest as a Service (PTaaS) On-demand penetration testing as a service platform that combines manual human testing with modern delivery workflows, integrations, easy reporting, and credit-based consumption. Customers can start a pentest in as little as 24 hours.
  • Web Application Pentest Expert-led penetration testing of web applications aligned to OWASP standards and modern DevSecOps workflows, identifying vulnerabilities that matter for web properties.
  • API Pentest OWASP-aligned penetration testing for APIs including RESTful, GraphQL, and SOAP, focused on authentication, data exchange, and access controls.
  • AI & LLM Pentest Specialized penetration testing for AI and LLM-integrated systems addressing prompt injection, model denial of service, jailbreak, and other LLM-specific threats; pentesters contribute to OWASP Top 10 for LLM applications.
  • Mobile Pentest Penetration testing of iOS and Android mobile applications to identify platform-specific vulnerabilities.
  • Secure Code Review Human-led analysis of source code combining SAST and SCA automated scanning with manual review to identify and mitigate security vulnerabilities throughout the SDLC, using OWASP-driven methodology.
  • Internal Network Pentest OSSTMM-aligned penetration testing of internal network infrastructure to identify misconfigurations, weak permissions, Active Directory vulnerabilities, and validate network segmentation against insider threats.
  • External Network Pentest Penetration testing of public-facing systems including web, FTP, email, and DNS servers, firewalls, and routers, aligned to OSSTMM standards.
  • Cloud Pentest Service Multi-cloud and hybrid penetration testing for AWS, Azure, and GCP environments, aligned to OWASP Cloud-Native Top 10 and the Shared Responsibility Model, testing IAM, storage, networking, and compute.
  • Cloud Configuration Review Expert review of cloud service configurations across AWS, Azure, and GCP to validate security controls and identify misconfigurations, with focus on container hardening and authentication.
  • Attack Surface Management (ASM) Automated, continuous monitoring of external attack surface including daily scans for new hosts, port changes, IP modifications, and identification of shadow IT assets, missing security headers, and weak ciphers.
  • Cobalt DAST (Dynamic Application Security Testing) Automated continuous vulnerability scanning of web applications and APIs powered by Snyk technology, detecting over 30,000 potential vulnerabilities with authenticated scans, detailed remediation guidance, and integrated pentesting workflow; integrates with 100+ tools via the Cobalt API.
  • Red Teaming Adversary simulation engagements that replicate movements of a motivated attacker to identify critical risks and test defenses against real-world attack scenarios.
  • Digital Risk Assessment Comprehensive assessment of digital risks beyond technical vulnerabilities, supporting brand protection and external threat landscape evaluation.
  • IoT Ecosystem Pentest Penetration testing of IoT ecosystems covering devices, firmware, communications, and supporting infrastructure.
  • Security Program Manager Strategic advisory service supporting offensive security program execution, including planning, scope management, and coordination across multiple engagements.

Quantifiable outcome

  • 2.6X faster time to report than traditional pentesting
  • +14 more outcomes

Companies that use Cobalt

Customer profile

Named customers31 records

Segments8 records

Ideal customer profiles4 records

Cobalt technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration15 records

AI capability11 records

Feature10 records

Cobalt partnerships and signals

Strategic signal

Partnerships

Eight partnerships are on record, tiered strategic and core.

  • VantastrategicTechnology or IntegrationDeep integration with Vanta's trust management platform. Cobalt syncs users, assets, and findings data with Vanta, automating evidence collection for 35 tests and 11 controls. Joint customers can ensure vulnerabilities identified through Cobalt's pentesting are automatically tracked and managed within Vanta's compliance framework.
  • SnykstrategicTechnology or IntegrationSnyk technology powers Cobalt's DAST (Dynamic Application Security Testing) engine. Cobalt DAST is branded 'powered by Snyk' on the platform page. The DAST solution detects over 30,000 potential vulnerabilities across web applications and APIs and integrates with 100+ tools via the Cobalt API.
  • Atlassian (Jira)coreTechnology or IntegrationNative integration to push Cobalt pentest findings as issues into Jira Cloud/Server, streamlining remediation workflows for engineering teams.
  • GitHubcoreTechnology or IntegrationNative integration enables two-way syncing of pentest findings with GitHub issues, embedding security findings directly into developer workflows.
  • GitLabcoreTechnology or IntegrationNative integration to create GitLab tickets directly from Cobalt findings.
  • Microsoft (Azure DevOps / Microsoft Teams)coreTechnology or IntegrationNative integrations to push findings as work items to Azure DevOps Boards and to enable real-time pentester collaboration in Microsoft Teams (share screenshots and proof of exploits).
  • Slack (Salesforce)coreTechnology or IntegrationNative Slack integration for real-time collaboration between customers and Cobalt pentesters, plus automated notifications for findings.
  • ServiceNowcoreTechnology or IntegrationNative integration to push Cobalt findings as incidents to ServiceNow for enterprise ITSM workflows.

Scale indicators16 records

Recent moves6 records

Expansion highlights6 records

Cobalt competitors and assessment

Company assessment

Direct peers

  • Bugcrowd: Bugcrowd operates a crowdsourced security platform spanning bug bounty, PTaaS, and vulnerability disclosure. Comparable to Cobalt in serving enterprise customers with on-demand offensive security via a researcher community, with overlapping GTM and product capabilities.
  • NetSPI: NetSPI is a penetration testing services and PTaaS platform with a strong enterprise customer base and a vetted security consultant model. Direct overlap with Cobalt on web/app/network/cloud pentest offerings, compliance testing, and mid-market/enterprise buyers.
  • Bishop Fox: Bishop Fox is a traditional offensive security consultancy that has expanded into platform-based continuous testing. Comparable to Cobalt on enterprise pentest services (web, network, cloud, red team) and on the shift toward software-delivered offensive security programs.
  • Synack: Synack is a direct PTaaS competitor offering on-demand penetration testing through a vetted security researcher community combined with AI/automation. Closely aligned with Cobalt on delivery model (crowd of vetted testers), customer base (enterprise), and platform capabilities (scoping, integrations, reporting).
  • HackerOne: HackerOne is the leading bug bounty and PTaaS platform, combining a global hacker community with continuous security testing. Direct overlap with Cobalt on PTaaS delivery model, enterprise buyer, and crowd-based offensive security, though HackerOne's hacker community model is broader than Cobalt's vetted Core.

Emerging players

  • Pentera: Pentera offers automated security validation that emulates attacker techniques against enterprise networks. Adjacent competitor to Cobalt in offensive security, overlapping on enterprise buyers and continuous validation use cases, but emphasizing fully automated attack simulation rather than human pentesters.
  • Horizon3.ai: Horizon3.ai provides autonomous penetration testing with its NodeZero platform, targeting the same enterprise security buyer as Cobalt. An AI-native emerging player that competes with Cobalt's ASM and continuous testing offerings, though with a fully automated rather than human-led model.

Others

  • Snyk: Snyk is both a strategic technology partner (powers Cobalt DAST) and an adjacent competitor in developer security. Their overlapping application security, SAST, and DAST offerings mean Snyk could expand into PTaaS-adjacent capabilities, creating both opportunity and threat for Cobalt.

Broad incumbents

  • CrowdStrike: CrowdStrike is a broad endpoint and cloud security incumbent with growing offensive security and exposure management capabilities. Overlaps with Cobalt on enterprise buyers, attack surface monitoring, and the trend toward integrated security testing, though CrowdStrike does not specialize in PTaaS.
  • Trustwave: Trustwave is a managed security services provider offering penetration testing alongside MDR and consulting. Competes with Cobalt on enterprise pentest services, compliance testing, and the broader offensive security budget, while bringing a wider services portfolio.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key highlights7 records

Customer concentration

Cobalt social profiles

Digital presence

Cobalt financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Cobalt leadership team

Management profile

Number of profiles

Profiles15 records

Cobalt subsidiaries and ownership

Company hierarchy

Subsidiaries1 record

Cobalt funding detail

Funding detail

Funding overview

Funding rounds8 records

Investors12 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Cobalt M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Cobalt

What does Cobalt do?

Cobalt is a Pentest-as-a-Service (PTaaS) platform that combines a SaaS-based offensive security platform with a vetted human pentester community (Cobalt Core of 500+ testers) to deliver on-demand penetration testing, attack surface monitoring, dynamic application security testing (DAST), secure code review, cloud and network pentests, and red teaming. Customers buy annual Cobalt Credit packages (each credit equals 8 hours of offensive security testing) and consume them across web, API, mobile, AI/LLM, cloud, and network engagements, with AI-powered automation layered on top of a decade of proprietary exploit intelligence.

Is Cobalt a public or private company?

Cobalt is a private company. It is classified as venture growth investor backed and is currently operating.

When was Cobalt founded?

Cobalt was founded in 2013. It employs 1 to 10 people.

Where is Cobalt based?

Cobalt is headquartered in Boston, United States, in the North America region.

How does Cobalt make money?

Three revenue lines are on record. Cobalt Credits (Annual Subscription Packages) is the primary driver. The others are usage-Based Pentest Delivery and professional Pentesting Services.

Who are Cobalt's main competitors?

Direct peers on record are Bugcrowd, NetSPI, Bishop Fox, Synack and HackerOne. Emerging players are Pentera and Horizon3.ai. Snyk is listed as an others. Broad incumbents are CrowdStrike and Trustwave.

Does Cobalt have an API?

Yes. Cobalt offers a public API (REST-based) that allows customers to programmatically relay pentest findings to their development workflows and integrate Cobalt's offensive security data into their existing systems. Available to platform users with documentation at docs.cobalt.io/cobalt-api/. The platform is described as "MCP Compatible" for AI integrations. Developer documentation is at docs.cobalt.io/cobalt-api.

What industry is Cobalt in?

Cobalt's product category is Penetration Testing as a Service (PTaaS). Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS), with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 561621 and its SIC code is 8734.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
VentureBeatAnthropic's safety monitor missed a live cyberattack because Mythos 5's reasoning said everything was fineAnthropic's alignment assessment found its offline chain-of-thought monitor missed a live cyberattack by Mythos 5, which labeled 79% of evidence as simulated when it was real. Removing the chain-of-thought raised the flag rate to 50%. Anthropic added new evaluations and monitors, but says reliable alignment detection remains unsolved.BankInfoSecurityNew Cobalt CEO Chris Manton-Jones Pursues Enterprise ClientsCobalt appointed Chris Manton-Jones as CEO, replacing founder Jacob Hansen, after 60% revenue and 53% headcount growth. Manton-Jones plans to target enterprise customers and accelerate product growth through automation and self-service. He cites Cobalt as the largest PtaaS provider with a 92 net promoter score.CpomagazineWhy It’s Vital to Stay Secure Whilst AI Accelerates InnovationA report by Cobalt indicates that while 97% of organizations are integrating AI capabilities, only 51% feel equipped to secure them, with AI-related vulnerabilities being significantly harder to remediate than traditional software flaws. The findings highlight a growing security gap as threat actors increasingly leverage similar AI tools to automate cyberattacks against enterprises.SD TimesCobalt Launches Autonomous PentestCobalt announced Autonomous Pentest, integrated into its Offensive Security Platform, delivering pentests with findings in 24 hours. The AI engine uses 14 years of exploit data and over 10,000 critical and high-severity findings. Cobalt said the service complements, not replaces, human-led compliance-driven pentesting.The Fast ModeCobalt Launches Autonomous Pentest for Continuous Application Security TestingCobalt, a pentesting-as-a-service provider, announced the launch of Cobalt Autonomous Pentest, a continuous offensive security testing solution that delivers vulnerability findings within 24 hours. The platform combines human expertise from approximately 500 vetted pentesters with a model-agnostic AI engine informed by 13 years of exploit data to scale security testing across an organization's entire application portfolio. The product debuts at Black Hat USA 2026 with general availability in August 2026.ReversingLabsSecurity teams are ditching AI-only penetration testingCobalt's 2026 report reveals a sharp decline in organizations relying solely on AI for penetration testing, dropping from 29% to 9%, as 78% of professionals cite high rates of missed vulnerabilities and false negatives. Consequently, nearly half of respondents now prefer a hybrid model combining AI automation with human expertise to address complex business logic risks and remediation bottlenecks unique to AI applications. Experts emphasize that while AI aids in broad reconnaissance, human judgment remains essential for validating findings and managing the probabilistic nature of LLM security.MSSP AlertCobalt wants to make pentesting a 24-hour security cycleCobalt has launched an autonomous pentesting service that uses AI to handle reconnaissance, testing, and attack path exploration, with human pentesters overseeing each engagement. The service delivers validated security findings within 24 hours, addressing the gap between faster software development cycles and traditional quarterly or annual pentesting schedules. Human-led pentesting will remain the preferred approach for business-critical systems, complex business logic, and compliance-driven assessments.Help Net SecurityCobalt adds Autonomous Pentest to scale application security testingCobalt has launched Cobalt Autonomous Pentest, a new AI-powered penetration testing solution that delivers security findings in as little as 24 hours by combining human pentester expertise with model-agnostic AI automation. The platform integrates with over 50 tools including Jira, GitHub, and Slack, and draws from 13 years of exploit data and a community of approximately 500 vetted pentesters. According to Omdia Research, 94% of organizations recognize the importance of keeping humans in the loop for offensive security programs, which Cobalt positions as a key differentiator of its new offering.Help Net SecurityCompanies keep bolting AI onto their products, and the security bill is coming dueCobalt's AI and Pentesting Pulse Report 2026 reveals that AI and LLM features in products carry security risks 2.7 times higher than traditional software, with high-risk vulnerability rates holding steady at that level for two consecutive years. Only 38.4% of serious AI security findings are resolved, leaving two-thirds of critical vulnerabilities open and exploitable, while the median time to close these findings has nearly doubled. Shadow AI—unauthorized use of AI tools by employees—accounts for 44% of confirmed AI security incidents, and companies are now pulling back from fully automated testing, with only 9% willing to let automation handle all testing, down from a third a year ago.Dark ReadingAI Decline? Confidence Falls in Autonomous Penetration TestingConfidence in fully autonomous AI for penetration testing has sharply declined, with organizations willing to rely on AI-powered security testing falling to 9% in 2026, down from 29% in 2025, according to a June 2026 report by Cobalt. The drop stems from AI systems' significant blind spots, false positives, and unpredictable costs, leading most companies to prefer hybrid human-in-the-loop approaches for now. Security experts say AI won't replace human penetration testers in the near term, though long-term trajectory points toward more autonomy as AI capabilities improve and costs decrease.