Cobalt.io Pricing Explorer
Cobalt.io Pricing Explorer
Compare pentest plans, estimate credits needed, and benchmark against HackerOne, Bugcrowd & Synack.
Annual Credit Estimator
Plan:
Web Apps:
API Tests / yr:
Mobile / yr:
Estimated annual spend: —
Key Takeaways
- Credits-based pricing – 1 credit ≈ 1 day of testing
- Typical web app pentest: 15–25 credits
- API pentest: 10–18 credits
- Annual plans: 100–1,000+ credits/yr
- Pro includes retests & SLA
- Fastest-growing modern PtaaS platform
Plans & Credits (2025)
| Plan | Starting Credits | Price per Credit | Best for |
|---|---|---|---|
| Core | 100+ | $320–$450 | Startups, occasional tests |
| Pro | 250+ | $280–$380 | Most SaaS & fintech |
| Enterprise | 500+ | $220–$320 | High-velocity, compliance-heavy |
Competitor Comparison (400 credits/yr)
Credits per year:
| Platform | Effective $/credit | Est. Annual Cost | Notes |
|---|---|---|---|
| Cobalt | — | — | Best SLA, fastest retests |
| HackerOne | ~$420 | — | More expensive, broader scope |
| Bugcrowd | ~$390 | — | Strong bug bounty focus |
| Synack | ~$550+ | — | Premium vetted researchers |
Gotchas
- Credits expire after 12 months
- Complex scopes can burn 30–50+ credits
- Retests cost extra on Core plan
- Minimum annual commitment on Pro+
Average Ratings
G2 Rating: 4.7 / 5 (680+ reviews)
Capterra: 4.8 / 5 (210+ reviews)
Based on verified reviews as of Dec 2025.
Common Complaints
- Credits feel expensive for small startups
- Occasional triage delays on Core
- Reporting templates less customizable
Common Praises
- Fastest findings delivery (often
- Excellent platform & Jira integration
- Unlimited retests on Pro/Enterprise
Cobalt Plans & Credit Pricing (2025)
| Plan | Credits Included | Price per Credit | Included Features |
|---|---|---|---|
| Core | 100–249 | $320–$450 | Standard testing, limited retests |
| Pro | 250–749 | $280–$380 | Unlimited retests, SLA, priority |
| Enterprise | 750+ | $220–$320 | Dedicated team, custom scopes, API |
Volume discounts apply automatically. All plans include platform access and findings triage.