Cobalt

Cobalt is an offensive security company that makes penetration testing easier to operationalize for modern security programs. It combines the Cobalt Offensive Security Platform with the Cobalt Core community of vetted pentesters so customers can launch engagements, review findings as they emerge, collaborate on remediation, and manage risk in one environment.

Its portfolio spans pentesting, secure code review, automated application scanning, cloud and network testing, AI and LLM assessments, digital risk assessment, and red teaming. Cobalt positions its services for organizations that want continuous, remediation-focused offensive security rather than point-in-time testing alone, especially where security, development, and operations teams need to work from the same workflow.

Offerings, Capabilities, and Integrations

Cobalt delivers offensive security coverage across application, network, cloud, AI, and external exposure use cases. Its model blends human-led testing with automation so teams can pair manual pentests with ongoing discovery and scanning, giving them broader visibility across web applications, APIs, cloud environments, and internet-facing assets.

The platform is designed to support the operational side of remediation as much as the testing itself. Cobalt centralizes assets, findings, schedules, trends, live collaboration, retesting, and reporting, while connecting findings into existing workflows through integrations with tools such as Jira, GitHub, Azure DevOps, ServiceNow, Slack, and Microsoft Teams.

Products and Services

  • Cobalt Offensive Security Platform: A centralized platform for scoping and scheduling tests, managing assets and findings, collaborating with testers in real time, and tracking offensive security performance over time.
  • Pentest as a Service (PTaaS): Cobalt’s on-demand pentesting model combines manual testing with a SaaS workflow so customers can start quickly, receive live findings, validate fixes through retesting, and generate stakeholder-ready reports and attestations.
  • Cobalt Core: A vetted community of pentesting experts that Cobalt matches to customer environments through a multi-stage process that includes technical assessment, interviews, and background checks.
  • AI & LLM Pentest: A specialized pentest for AI- and LLM-enabled applications that targets issues such as prompt injection, model denial of service, sensitive prompt exposure, and related API and web application risks.
  • Secure Code Review: A human-led secure code review service that combines automated source-code scanning with manual validation and an OWASP-driven methodology to identify exploitable flaws and design issues earlier in the SDLC.
  • Dynamic Application Security Testing (DAST): An automated scanning capability for web applications and APIs that supports continuous monitoring, authenticated scans, remediation validation, and detailed findings inside the Cobalt platform.
  • Cloud Pentest Service: A cloud security testing service for environments in AWS, Microsoft Azure, and Google Cloud that helps identify vulnerabilities, assess controls, and support security and compliance objectives.
  • Attack Surface Management: An attack surface discovery and monitoring capability that scans customer domains to identify externally reachable assets, monitor changes, and surface targets that may require further testing.
  • Red Teaming: A red team service that simulates real-world attacker behavior to evaluate security controls, expose high-impact weaknesses, and test SOC readiness.
  • Digital Risk Assessment: An external-facing assessment that uses OSINT and publicly available information to identify exposed assets, leaked credentials, impersonation risks, and other threats to brand and business exposure.
  • Application Pentest Service: A service for testing web applications, mobile apps, APIs, and AI-enabled applications with real-time collaboration, remediation workflows, and support for both agile and comprehensive test scopes.
  • Network Pentest Service: A network security testing service for internal and external environments that emphasizes flexible scheduling, audit-quality findings, and reporting aligned to compliance and customer requirements.

Target Customers

Cobalt is aimed at security, application security, development, operations, InfoSec, SOC, and GRC teams that need offensive security testing to fit into day-to-day engineering and remediation workflows. Its delivery model is especially relevant for teams that want direct collaboration with testers and visibility into findings while work is still in progress.

The company serves organizations with modern digital estates that include applications, APIs, cloud infrastructure, and AI-enabled systems, as well as businesses that need audit-quality attestations for customers, auditors, or compliance programs. Its offerings also align with companies building more continuous offensive security programs, from growing businesses to large enterprises managing broad attack surfaces.

Cloud Integrations and Marketplace

  • Microsoft Marketplace: Cobalt has a verified Microsoft Marketplace presence through its Microsoft Teams integration, which lets customers discover and deploy the integration and collaborate with pentesters directly inside Microsoft Teams.

Key People

  • Sonali Shah: Chief Executive Officer
  • Gunter Ollmann: Chief Technology Officer
  • Chris Essex: Chief Revenue Officer
  • Lisa Matherly: Chief Marketing Officer
  • Andrew Obadiaru: Chief Information Security Officer
  • Jason Lamar: SVP of Product
  • Rosie Carley: Chief People Officer
  • Martin Rannje: Senior VP of Finance
  • Paul Zymba: Senior VP of Customer Success

Key Facts

  • Headquarters: San Francisco, California, United States
  • Employees: 201-500
  • Annual Revenue: Undisclosed
  • Parent Company: None
  • Subsidiaries: Cobalt Labs UK Limited; Cobalt Labs Germany GmbH
  • Publicly Listed: Private

Analyst Recognitions

  • Gartner: 2025 Gartner Hype Cycle for Application Security — Sample Vendor in Penetration Testing as a Service (PTaaS). 2025 Gartner Hype Cycle for Security Operations — Sample Vendor in Penetration Testing as a Service (PTaaS). 2025 Gartner Hype Cycle for XaaS — Sample Vendor in Penetration Testing as a Service (PTaaS).
Cobalt

Enter a search