Cobalt’s cover photo
Cobalt

Cobalt

Computer and Network Security

San Francisco, California 36,041 followers

Offensive security testing for security and development teams.

About us

Cobalt is the pioneer in pentesting as a service and a leader in offensive security services. We are focused on combining talent and technology with speed, scalability, and expertise. Thousands of customers and hundreds of partners rely on the Cobalt Offensive Security Platform, along with 500+ trusted pentesters, to find and fix vulnerabilities across their environments. By enabling faster pentest launches, real-time collaboration with pentesters, and seamless integration with remediation workflows, we help organizations identify critical issues and accelerate risk mitigation so they can operate fearlessly and innovate securely.

Website
https://cobalt.io
Industry
Computer and Network Security
Company size
201-500 employees
Headquarters
San Francisco, California
Type
Privately Held
Founded
2013
Specialties
Web security, Vulnerability management, Application security, Web Application Security, Mobile Application Security, API Security, pentesting, and pentesting as a service

Products

Locations

Employees at Cobalt

Updates

  • View organization page for Cobalt

    36,041 followers

    Register now to receive the full report on April 21st and gain data-driven insights on vulnerability management and remediation performance → https://hubs.la/Q049CGs10 2025 was a wake-up call. Confidence in security posture remained high, but gaps in remediation and rising risk—especially around AI—told a different story. The question now is: how are leading teams adapting? The 2026 State of Pentesting Report provides a comprehensive look at how your peers are navigating modern pentesting challenges and integrating AI-driven defenses into their security programs. From shifting priorities to evolving approaches, it offers a clearer picture of what effective security looks like today. #cybersecurity #infosec #pentesting

  • Cobalt reposted this

    AI agents are starting to act on behalf of users. That introduces a new identity layer most security programs weren’t designed to handle. Permissions aren’t as tightly tied to individuals, actions can happen asynchronously, and traditional access controls don’t always reflect how these systems behave in practice. Many teams are moving quickly to adopt AI, but governance and identity models aren’t keeping up. That gap is where risk starts to accumulate. On April 7 from 12:00–1:00 p.m. ET, I’ll be speaking in a session, Securing AI Agents and Copilots: The New Identity Layer (and How to Govern It), hosted by Business Intelligence Group. It’s a practical, vendor-neutral discussion focused on what security and governance teams can implement now. We’ll cover where current models break down and how to avoid introducing new blind spots. If you’re working through AI adoption or thinking about governance, this should be relevant. I hope to see you there. Register here: https://hubs.la/Q049vCn80

  • View organization page for Cobalt

    36,041 followers

    🔦 New Pentester Spotlight: Meet Orhan Yildirim! Not every pentester takes the same path into cybersecurity and that’s exactly the point. ☄️ Orhan, a Cobalt Core member, has worked on 400+ security projects and brings a deeply technical, automation-driven approach to his craft. From scaling pentesting through scripting and tooling to what keeps him motivated, Orhan shares what it takes to stay effective across hundreds of engagements. He also talks about why he enjoys being part of the Cobalt Core and what customers and the media often misunderstand about pentesters. Read the full spotlight → https://hubs.la/Q049vx2J0 #pentesting #cybersecurity #infosec

  • View organization page for Cobalt

    36,041 followers

    #BrainsAndBots: Speed matters, but so does access. We’re spotlighting two capabilities that make security workflows faster, more intuitive, and easier to act on: AI-powered Documentation: Ask questions naturally and get direct, intent-based answers without digging through keyword-heavy docs. Find what you need faster and spend less time searching for guidance. MCP Compatible: Securely connect AI assistants to Cobalt data to automate repetitive tasks like triaging findings, checking pentest status, and correlating risks—all through natural language. Less friction, faster decisions, and a smoother path from discovery to remediation. #cybersecurity #pentesting #infosec #ai

  • Cobalt reposted this

    Another #RSAC in the books, and one thing feels clear: security is at an inflection point. Across conversations this week, the same themes kept coming up—faster development cycles, expanding attack surfaces, and the growing role of AI on both sides. The pace is picking up, and a lot of current approaches just aren’t built for it. At Cobalt, we’ve been focused on what this next phase looks like. Last week, we introduced new AI capabilities designed to handle the scale and speed of modern environments, while giving human experts the space to focus on what matters most: thinking like real attackers. Grateful for the conversations, the energy, the challenges, and the perspectives shared throughout the week. More to come.

    • No alternative text description for this image
    • No alternative text description for this image
  • View organization page for Cobalt

    36,041 followers

    Faster releases, expanding attack surfaces, and rising expectations from the business are changing what “good” looks like. But many teams are still operating without clear answers to a few critical questions: How long is your true window of exposure? Where are engineering bottlenecks slowing remediation? Are you operating reactively…or programmatically? These are the questions shaping modern offensive security programs and separating leading teams from the rest. Our upcoming report explores these shifts using data from thousands of penetration tests across web, API, LLM, network, and mobile environments, alongside insights from a 450-respondent survey. Inside, we'll break down: • How your remediation timelines and SLAs compare to industry benchmarks • Where security leaders are focusing investments to address emerging threats • How teams are adapting their testing strategies in response to AI Register now to receive the full report when it comes out → https://hubs.la/Q0495XLT0 #cybersecurity #infosec #pentesting

  • View organization page for Cobalt

    36,041 followers

    ✈️ Cobalt is headed to the CypherCon Hacker Conference in Milwaukee! From April 1-2, stop by our booth to learn more about the Cobalt Core, chat about the Cobalt Offensive Security Platform, and hear how we’re helping organizations identify security issues at scale and reduce risk. We’ll also host a raffle at our booth where you can enter for a chance to win a Flipper Zero and Cobalt swag, so come say hello! More information here → https://hubs.la/Q048Zjz00 #cybersecurity #pentesting #infosec

  • View organization page for Cobalt

    36,041 followers

    We’ve romanticized the “lone wolf hacker” for years, but the data tells a different story. 98% of elite pentesters prefer working in structured, collaborative environments over bug bounty programs. Why? Because the hardest vulnerabilities don’t come from racing for low-hanging fruit. They come from going deep. 💪 If you want to understand how the best pentesters actually work today, this report breaks it down. Download → https://hubs.la/Q048WNWp0 #cybersecurity #infosec #pentesting

  • View organization page for Cobalt

    36,041 followers

    “We've been working with Cobalt for years before they started offering LLM pentesting. We knew Cobalt was committed to staying at the forefront of industry best practices, so when we started developing LuLu, it was a no-brainer to continue to work with them.” – Waylan Wong, Cloud Engineering, Sr. Manager, Zest AI When Zest AI secured its lending intelligence assistant, they weren’t just testing another application—they were validating an entirely new attack surface. Working with Cobalt, they identified and remediated a prompt injection vulnerability that could have exposed sensitive data, while also strengthening their overall security posture. Because when AI is involved, security can’t be an afterthought! Read on → https://hubs.la/Q048W6Zt0 #cybersecurity #infosec #pentesting #ai

  • View organization page for Cobalt

    36,041 followers

    The "annual pentest" is a dangerous snapshot in a real-time world. 🗓️ If your attack surface changes daily, a once-a-year report leaves a massive gap between discovery and defense. That’s why the shift to Continuous Threat Exposure Management (CTEM) is so critical. By moving from a "check-the-box" event to a continuous validation cycle with PTaaS, you stop firefighting and start managing risk at the speed of your business. Stop waiting for the calendar to tell you if you're secure. Read on → https://hubs.ly/Q048LWl40 #cybersecurity #infosec #pentesting

Similar pages

Browse jobs

Funding

Cobalt 7 total rounds

Last Round

Series B

US$ 29.0M

See more info on crunchbase