Cyber

A Cobalt alternative that never needs scheduling

Cobalt made pentesting faster to buy, turning a months-long procurement into a few days. CloudThinker Cyber removes the booking step altogether: testing fires when your code changes, every finding arrives with a working exploit, and the fix comes back as a merge request.

  • No scheduling, no test window
  • Proof, then the merge request
  • Retested after merge

New to the category? Start with what Continuous Offensive Security Testing means.

Straight answer

Cobalt solved a real problem, and humans still matter

Before PTaaS, buying a pentest meant a procurement cycle, a statement of work and a wait measured in months. Cobalt compressed that to days on a mature platform with a vetted tester community and published pricing. That was a genuine improvement, and the compliance evidence it produces is recognised everywhere.

Human testers also remain better than any autonomous system at genuinely novel attack ideas, lateral thinking across systems, and the judgement calls a regulator wants a name attached to. This page is not an argument that you should stop using people. It is an argument about what should happen in the fifty-one weeks when no engagement is running.

The real question

What happens between engagements?

The gap is where the risk lives

A two-week engagement twice a year leaves roughly forty-eight weeks of merges that nobody tested. The report describes a version of the application that stopped existing shortly after it was written.

Retest is a separate purchase

In the scheduled model, confirming that your fix actually worked is usually billed separately and booked months out, so exposure windows stay open long after engineering believes they closed them.

The patch is still yours to write

A human report ends with recommendations. Every line of remediation code is written by your engineers, competing for attention with the roadmap, which is where most of the calendar time actually goes.

Coverage is sampled, not tracked

Testers prioritise within a fixed window, which is the correct approach for a human engagement and means coverage is a sample rather than a tracked surface that grows with your product.

The difference

Testing that fires when the code changes

Not faster scheduling. No scheduling, because the trigger is the merge itself.

Trigger-driven and incremental

Runs start on a deployment, a new asset, a fresh CVE or configuration drift. Each run scopes itself to what the change touched, and every previously proven finding replays as a regression, so per-merge testing is realistic.

Deep product context

Agents learn intended behaviour from your OpenAPI spec, roles and source, then test what breaks it. Tenant isolation, payment flows and privilege boundaries get tested continuously rather than only when a human happens to look.

Remediation inside the loop

The patch is drafted from your codebase and linked to the finding. Merge it and the agents replay the original attack path, so the retest is included rather than quoted.

Leaves the human work to humans

Continuous coverage of known attack classes frees a periodic human engagement to do what people are genuinely better at: novel logic, creative chaining, and the judgement a regulator wants signed.

An honest comparison

Cobalt vs CloudThinker Cyber

A human engagement on a fast platform, versus a continuous machine loop. Most mature programmes end up running both.

DimensionCobaltCloudThinker Cyber
ModelHuman testers delivered through a platformAutonomous agents with independent validation
What starts a testA booking, typically days to scheduleA deployment, new asset, CVE, or configuration drift
CadencePeriodic engagementsEvery approved release
CoveragePrioritised sample within the windowThe mapped surface, re-tested as it changes
RemediationRecommendations in a reportPatch drafted from your code as a merge request
RetestUsually a separate engagementAutomatic replay of the original attack path
Novel attack creativityStrong, human testers still lead hereStrong on known classes chained at machine scale

Comparison based on publicly published product information as of August 2026. Verify current capabilities and pricing directly before deciding.

Governed by design

Full autonomy, your rules of engagement

Autonomous describes who drives, not whether anyone set the boundaries. Every control here is enforced by the platform rather than promised in a document.

Production excluded by default

Runs stay inside the environments you approve. Adding production is an explicit decision, never an accident of configuration.

Non-destructive proof

Exploits are reproduced with read-only methods where they exist, designed to confirm the path without mutating customer data.

Rate-limited and scoped

Traffic is throttled and locked to the rules of engagement you set, so a test does not become an availability incident.

Full audit log

Every request an agent sends is recorded, reviewable and exportable, for your security team now and an auditor later.

One platform

More than offensive security

Cyber is one module in an AgenticOps platform. The agents that attack your application share connections, memory and policy with the ones that resolve incidents, cut cloud spend, and review the pull request that introduced the flaw.

Shared context

The same connection graph that tells the incident agent which service depends on which tells Cyber which endpoint is genuinely reachable.

One governance model

Brokered credentials, sandboxed execution and tamper-evident audit apply identically whether an agent is testing an API or resizing a node group.

One approval surface

Graduated autonomy is configured once per environment, so the rules that govern remediation govern offensive testing too.

FAQ

Cobalt alternative questions

What is the best Cobalt alternative?

If you want another human-delivered PTaaS platform, the usual comparisons are HackerOne, Synack, BreachLock, NetSPI and Bugcrowd, which differ mainly on tester bench, pricing model and compliance coverage. If the thing you actually want to fix is the gap between engagements, the alternative is not another PTaaS vendor but a continuous model: CloudThinker Cyber tests on every change and closes findings with a drafted merge request.

Does CloudThinker Cyber replace human penetration testing?

Not entirely, and we would not recommend treating it that way. It replaces the repetitive, cadence-bound part: re-testing the same surface after every release. Human testers remain better at novel attack ideas, lateral thinking across systems, and regulatory sign-off. The realistic pattern is Cyber continuously, with a human engagement periodically for depth and attestation.

Will CloudThinker Cyber satisfy my compliance requirement?

For application security evidence, generally yes: OWASP API Top 10 coverage with per-run evidence for SOC 2, ISO 27001 and PCI DSS, plus a full exportable log of every request an agent sent. Some frameworks and some customers specifically require an independent human-attested penetration test, and where that is the case a periodic human engagement is still required alongside continuous testing.

How does pricing compare to a Cobalt engagement?

The models differ more than the numbers. A PTaaS engagement is priced per project, with retests usually billed separately, so cost scales with how often you want to know. Cyber is priced by target and attack surface, so cost scales with what you run rather than how often you test it. Teams shipping daily generally find the second cheaper per unit of assurance, which is a statement about frequency rather than a claim to be cheap.

Can I use Cobalt and CloudThinker Cyber together?

Yes, and it is a common pattern. Cyber covers every release continuously and keeps exposure windows short, while an annual or semi-annual human engagement provides the independent, attested deep dive that auditors and enterprise customers ask for. The human testers also arrive at a cleaner target, because the routine findings were closed months earlier.

The Intelligent OS for your Cloud

Put your cloud operations on agentic speed

Investigate incidents, optimize cost, secure applications, and review code — under your policies, approvals, and audit trail.