Secure every application with flexible pentesting that combines expert-led testing, autonomous validation, and actionable results.
Learn moreIdentify exploitable risk across external networks, internal infrastructure, and cloud environments.
Learn moreExtend your offensive security program with specialized assessments, adversarial testing, code review, and program-level support.
Learn moreFor teams in need of a speedy, annual pentest to meet a compliance need
or client request.
For teams looking to build
a structured pentest program
to meet compliance needs and
improve overall security.
For teams looking to scale their pentest programs to meet compliance needs, increase testing frequency, and improve overall security.
SAML-Based SSO
Attack Surface Monitoring (ASM)
Custom Pentester Requests (Geo, Time Zone, Testing Windows)
Standard
Pool
Premium
Named CSM
Annual
Enterprise
Named CSM
Quarterly
AUTONOMOUS PENTEST
Test every release, cover every application, and stay ahead of AI-augmented threats.
Cobalt Autonomous Pentest pairs AI systems with elite Cobalt Core pentesters to deliver continuous offensive security across your full application portfolio. Built on 13 years of real-world exploit data, with our Core pentesters directing scope, execution, and quality on every engagement.
What's included
New customers and existing customers on any credit tier are eligible for the promotional $3,500 per test offer.* Autonomous Pentest must be initiated and completed before Dec 31st 2026 in order to qualify.
*The exact number of credits debited from your account may vary based on your contracted rate per credit.
A Cobalt Credit is a standardized unit of work that represents the equivalent of 8 pentesting hours—delivered through a combination of AI-powered automation and human expertise. Credits provide flexibility in both planning and executing pentests. They are sold in annual packages that include platform access, test orchestration, expert validation, reporting, and more. The amount of credits required to test a specific asset will depend on the scope and delivery options of each test.
Credits do not roll over into the next contract. To keep your momentum going, credits are specific to each contract year. This structure ensures you have a dedicated budget to maximize your results every single year.
Our PTaaS model provides unlimited on-demand retesting throughout your contract term. This ensures that every fix your team implements is rigorously validated and that your assets remain secure as you evolve.
Yes, credits are available throughout your contract which enables teams flexibility in case of last minute product launches or security concerns arise.
Empower your security and development teams with Cobalt’s unique combination of a modern SaaS platform and our community of vetted security experts. Trust the pioneers of PtaaS as your offensive security partner across your entire attack surface.