Cobalt

United States

Service types
  • Pen tester
Industries served
  • SaaS
  • Technology

Penetration testing and security testing services

Cobalt combines penetration-testing services with a platform for findings and reports. Compare asset coverage, manual work, report types, remediation review, and retesting terms for the proposed package.

Source checked September 23, 2026 · View official source

Company sizes served
  • early-stage
  • mid-market
  • enterprise

Documented services

Cobalt's services page describes penetration testing across applications, APIs, and networks. Its report documentation describes report types whose contents vary, including scope, methodology, findings, and remediation information. Its remediation documentation distinguishes submitting a fix for retest from accepting a risk, with availability subject to contract conditions.

Engagement considerations

Bring an asset inventory, representative roles, authorized environments, and the decision the test should support. Ask how the proposed test addresses those workflows and how manual work relates to automated tools. Request a sanitized report matching the package under consideration.

Follow an example finding through assignment, a deployed change, retest submission, tester response, and report update. Check how unresolved issues and accepted risks remain visible. Confirm who can access technical details and what export can support a customer request.

Questions to verify in a consultation

  • Which assets, roles, environments, and manual testing are included?
  • Who is assigned to the test and who reviews findings?
  • Which report type and finding details are available?
  • Which retest period, conditions, rounds, and fees apply?
  • What records remain accessible or exportable after the contract ends?

Scope to confirm

Compare testing work, platform access, scheduling, report formats, retesting, and exclusions in writing. Do not treat a catalog of services as the scope of one test. This profile summarizes public materials; it does not establish testing quality or results for your environment.

Scope a penetration test · Build a testing brief · Review the resulting report

Buying content reviewed October 1, 2026. Public sources; no firsthand service evaluation.