Cobalt, founded in 2013, operates a model that's less about heroic one-off engagements and more about continuous security testing baked into the development lifecycle. The core idea: pair a SaaS platform with a live community of 500+ vetted pentesters (Cobalt Core) to surface vulnerabilities in real time, not months after the audit. The platform handles orchestration - scheduling, collaboration, reporting - while the community delivers the human expertise scanners miss. Organizations get transparency into findings as they happen, which compresses the window between discovery and remediation.
The threat model here is straightforward: modern software ships fast, and traditional pentest cycles can't keep up. Cobalt targets that gap across security testing, pentesting, and vulnerability assessment domains, serving thousands of customers through the platform and coordinating with hundreds of partners. The technical stack bridges automation and manual research - tools that facilitate continuous engagement rather than point-in-time snapshots.
The company is remote-first, with team members distributed across multiple time zones. Cobalt describes its mission as fixing how the security industry operates - replacing opaque, slow-motion audits with something more transparent and iterative. Whether that's idealistic or just pragmatic probably depends on how many breach reports you've read lately.






