Skip to content
Z Zendikt
C

Cobalt review and pricing

PTaaS pure-play for SOC 2 and PCI mid-market compliance work.

By Cobalt Labs, Inc. · Founded 2013 · San Francisco, CA · private

Cobalt is the PTaaS pure-play category leader, founded 2013 by Jacob Hansen and Christian Hansen and pivoted in 2016 from a bug-bounty platform (then "Crowdcurity") to scheduled, vetted-researcher PTaaS. The company raised $29M Series B in 2022 (Highland Europe lead), and over 2023-2025 pivoted aggressively from a developer-tooling brand to a compliance-driven sales motion targeting SOC 2 Type 2, PCI DSS, and ISO 27001 attestations. Strengths: PTaaS-focused since 2016 (the category Cobalt arguably defined commercially), strong fit for mid-market compliance work (typical engagement: 1-2 week SOC 2-quality web app test with auditor-ready report), the "Cobalt Core" vetted-researcher pool (1,000+ background-checked testers), and mature retest workflow with included free retests within 6 months. Best fit for mid-market organizations (200-2,500 employees) running compliance-driven testing cycles (SOC 2 Type 2, PCI, ISO 27001) where speed-to-engagement and auditor-acceptable reports matter more than the largest researcher pool. Trade-offs: pivot to compliance-driven sales 2023+ has dropped some of the developer-experience polish that drove early adoption; researcher pool is meaningfully smaller than HackerOne and Bugcrowd; pricing escalated meaningfully at renewal 2024-2025; and Fortune 500 logo coverage is thinner than the bug-bounty leaders.

Best for

Mid-market organizations (200-2,500 employees) running compliance-driven testing cycles (SOC 2 Type 2, PCI DSS, ISO 27001), particularly SaaS companies and fintechs needing fast, auditor-acceptable web app and API pen tests with retests included.

Worst for

Fortune 500 enterprises wanting the largest researcher pool (HackerOne / Bugcrowd better), federal buyers requiring cleared researchers (Synack better), EU buyers requiring strict data residency (Intigriti / YesWeHack better), or buyers wanting fully-managed continuous bug bounty.

Vendor Trust Score

Is Cobalt a trustworthy vendor?

7.6/10
Mixed
Pricing transparency
Published rates; no hidden fees
7.0
Contract fairness
Reasonable terms; no auto-renew traps
7.5
Incident response
How they handle outages and breaches
8.0
Post-acquisition behavior
Customer treatment after M&A or PE
8.0
Executive stability
Leadership churn over 24 months
7.5
Roadmap honesty
Public commitments held
7.5
Trust signal log
  • 2022-04-12
    Series B raised $29M led by Highland Europe; growth capital secured for PTaaS expansion
  • 2023-06-15
    Pivot to compliance-driven sales messaging; positioning shifted from developer-tooling brand to SOC 2 / PCI / ISO 27001 focus
  • 2024-03-22
    Cobalt Core researcher pool crossed 1,000+ vetted testers; expanded specialty coverage (mobile, IoT)
  • 2024-09-22
    Pricing escalation reported at renewal; engagement-credit pricing increased 10-15% for renewing customers
  • 2025-04-15
    Free retest window expanded; included retests within 6 months of engagement close
Vendor Trust is scored independently of product quality. A great product from an unfair vendor still earns a low trust score.
Review Intelligence

What 240 reviews actually say

Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.

Last synthesized
2026-04-30

Praise patterns

  • Fast time-to-engagement (typically <2 weeks)
    87%
  • Auditor-ready reports for SOC 2 / PCI / ISO 27001
    78%
  • Free retests within 6 months valued
    71%
  • Cobalt Core researcher quality consistent
    64%

Complaint patterns

  • Pricing escalation reported at renewal
    47%
  • Researcher pool smaller than HackerOne / Bugcrowd
    41%
  • Specialty engagement scope-creep charges
    38%
  • Compliance-pivot reduced developer-experience polish
    31%
Sentiment trend (6 months)
85/100 +1 pts
12
01
02
03
04
05
Patterns are extracted from review corpus and human-verified. We surface trends, not anecdotes.
Verified Pricing

What buyers actually pay

142 anonymized deal disclosures · last updated 2026-05-01

Contribute your deal price
Company size Median annual
Single engagement (web app) $18,000
Annual platform (mid-market) $96,000
Enterprise unlimited $320,000
Verified pricing is crowdsourced from buyers under anonymity guarantees. Vendor-listed prices are validated against actual deals quarterly.
Compliance & Security

Auto-verified certifications

Verified 2026-05-01
SOC 2 Type II
ISO 27001
HIPAA
GDPR
CCPA
PCI DSS
FedRAMP

Editorial: Strengths

  • PTaaS pure-play since 2016 (category-defining commercial PTaaS)
  • Strong fit for SOC 2 / PCI / ISO 27001 mid-market compliance work
  • Cobalt Core vetted-researcher pool (1,000+ background-checked testers)
  • Mature retest workflow (free retests within 6 months)
  • Fast time-to-engagement (typically <2 weeks scheduling)
  • Mature integrations (Jira, ServiceNow, Slack, GitHub)
  • $29M Series B 2022 (Highland Europe)

Editorial: Weaknesses

  • Pivot to compliance-driven sales 2023+ has reduced developer-experience focus
  • Researcher pool meaningfully smaller than HackerOne / Bugcrowd
  • Fortune 500 logo coverage thinner than bug-bounty leaders
  • Pricing escalation reported at renewal 2024-2025
  • Limited bug-bounty product (PTaaS-focused, not bounty-first)

Key features & integrations

  • +Cobalt Core vetted-researcher pool (1,000+ testers)
  • +Web app, API, mobile, cloud, and network pen testing
  • +Free retests within 6 months
  • +Auditor-ready PDF reports (SOC 2, PCI, ISO 27001 mapped)
  • +Real-time finding stream during engagement
  • +Mature Jira, ServiceNow, Slack, GitHub integrations
  • +Dedicated security advisor
  • +Compliance-mapped reporting templates
40+ integrations
JiraServiceNowSlackGitHubGitLabAzure DevOpsSplunk
Geography supported
Global; strongest in US, EU, UK
Best fit
100 to 5,000 employees · SaaS, fintech, and mid-market compliance-driven security programs
Editorial deep-dive

Read our full ranking of Penetration Testing as a Service (PTaaS)

Cobalt ranks #2 in our editorial review of 10 penetration testing as a service (ptaas) platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.

Read the full ranking

Closest alternatives in Penetration Testing as a Service (PTaaS)

Help the next buyer

Contribute your verified deal price

Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for Cobalt; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).

Submit anonymously