Cobalt made pentesting faster to buy, turning a months-long procurement into a few days. CloudThinker Cyber removes the booking step altogether: testing fires when your code changes, every finding arrives with a working exploit, and the fix comes back as a merge request.
New to the category? Start with what Continuous Offensive Security Testing means.
Before PTaaS, buying a pentest meant a procurement cycle, a statement of work and a wait measured in months. Cobalt compressed that to days on a mature platform with a vetted tester community and published pricing. That was a genuine improvement, and the compliance evidence it produces is recognised everywhere.
Human testers also remain better than any autonomous system at genuinely novel attack ideas, lateral thinking across systems, and the judgement calls a regulator wants a name attached to. This page is not an argument that you should stop using people. It is an argument about what should happen in the fifty-one weeks when no engagement is running.
A two-week engagement twice a year leaves roughly forty-eight weeks of merges that nobody tested. The report describes a version of the application that stopped existing shortly after it was written.
In the scheduled model, confirming that your fix actually worked is usually billed separately and booked months out, so exposure windows stay open long after engineering believes they closed them.
A human report ends with recommendations. Every line of remediation code is written by your engineers, competing for attention with the roadmap, which is where most of the calendar time actually goes.
Testers prioritise within a fixed window, which is the correct approach for a human engagement and means coverage is a sample rather than a tracked surface that grows with your product.
Not faster scheduling. No scheduling, because the trigger is the merge itself.
Runs start on a deployment, a new asset, a fresh CVE or configuration drift. Each run scopes itself to what the change touched, and every previously proven finding replays as a regression, so per-merge testing is realistic.
Agents learn intended behaviour from your OpenAPI spec, roles and source, then test what breaks it. Tenant isolation, payment flows and privilege boundaries get tested continuously rather than only when a human happens to look.
The patch is drafted from your codebase and linked to the finding. Merge it and the agents replay the original attack path, so the retest is included rather than quoted.
Continuous coverage of known attack classes frees a periodic human engagement to do what people are genuinely better at: novel logic, creative chaining, and the judgement a regulator wants signed.
A human engagement on a fast platform, versus a continuous machine loop. Most mature programmes end up running both.
| Dimension | Cobalt | CloudThinker Cyber |
|---|---|---|
| Model | Human testers delivered through a platform | Autonomous agents with independent validation |
| What starts a test | A booking, typically days to schedule | A deployment, new asset, CVE, or configuration drift |
| Cadence | Periodic engagements | Every approved release |
| Coverage | Prioritised sample within the window | The mapped surface, re-tested as it changes |
| Remediation | Recommendations in a report | Patch drafted from your code as a merge request |
| Retest | Usually a separate engagement | Automatic replay of the original attack path |
| Novel attack creativity | Strong, human testers still lead here | Strong on known classes chained at machine scale |
Comparison based on publicly published product information as of August 2026. Verify current capabilities and pricing directly before deciding.
Autonomous describes who drives, not whether anyone set the boundaries. Every control here is enforced by the platform rather than promised in a document.
Runs stay inside the environments you approve. Adding production is an explicit decision, never an accident of configuration.
Exploits are reproduced with read-only methods where they exist, designed to confirm the path without mutating customer data.
Traffic is throttled and locked to the rules of engagement you set, so a test does not become an availability incident.
Every request an agent sends is recorded, reviewable and exportable, for your security team now and an auditor later.
Cyber is one module in an AgenticOps platform. The agents that attack your application share connections, memory and policy with the ones that resolve incidents, cut cloud spend, and review the pull request that introduced the flaw.
The same connection graph that tells the incident agent which service depends on which tells Cyber which endpoint is genuinely reachable.
Brokered credentials, sandboxed execution and tamper-evident audit apply identically whether an agent is testing an API or resizing a node group.
Graduated autonomy is configured once per environment, so the rules that govern remediation govern offensive testing too.
If you want another human-delivered PTaaS platform, the usual comparisons are HackerOne, Synack, BreachLock, NetSPI and Bugcrowd, which differ mainly on tester bench, pricing model and compliance coverage. If the thing you actually want to fix is the gap between engagements, the alternative is not another PTaaS vendor but a continuous model: CloudThinker Cyber tests on every change and closes findings with a drafted merge request.
Not entirely, and we would not recommend treating it that way. It replaces the repetitive, cadence-bound part: re-testing the same surface after every release. Human testers remain better at novel attack ideas, lateral thinking across systems, and regulatory sign-off. The realistic pattern is Cyber continuously, with a human engagement periodically for depth and attestation.
For application security evidence, generally yes: OWASP API Top 10 coverage with per-run evidence for SOC 2, ISO 27001 and PCI DSS, plus a full exportable log of every request an agent sent. Some frameworks and some customers specifically require an independent human-attested penetration test, and where that is the case a periodic human engagement is still required alongside continuous testing.
The models differ more than the numbers. A PTaaS engagement is priced per project, with retests usually billed separately, so cost scales with how often you want to know. Cyber is priced by target and attack surface, so cost scales with what you run rather than how often you test it. Teams shipping daily generally find the second cheaper per unit of assurance, which is a statement about frequency rather than a claim to be cheap.
Yes, and it is a common pattern. Cyber covers every release continuously and keeps exposure windows short, while an annual or semi-annual human engagement provides the independent, attested deep dive that auditors and enterprise customers ask for. The human testers also arrive at a cleaner target, because the routine findings were closed months earlier.
Investigate incidents, optimize cost, secure applications, and review code — under your policies, approvals, and audit trail.