main logo icon

Published on

September 5, 2026

|

13 min read

Cobalt vs Stingrai (2026): Credits vs Fixed-Price, Autonomous vs Snipe, Retest Terms

A sourced head-to-head of Cobalt and Stingrai for 2026: the credit model against fixed published pricing, Cobalt Autonomous Pentest against Snipe, retest terms, compliance evidence, and which company profile each one fits. Every claim links to its source.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Cobalt and Stingrai sell penetration testing on two different commercial shapes. Cobalt sells annual credit packages, where one Cobalt Credit represents the equivalent of 8 hours of offensive security testing, drawn down against tests booked in a portal and started in 1 to 3 business days depending on tier. Stingrai sells a fixed price per scoped engagement: US$3,000 for an Autonomous Pentest run by Snipe, US$6,800 for a Hybrid Pentest with penetration testers testing alongside Snipe throughout, or the same tiers as continuous 12-month programs at US$450 and US$1,275 per month. On autonomous testing the two are closer than the marketing suggests, and Cobalt is unusually honest about the limits. Cobalt Autonomous Pentest returns a complete test in 24 hours with Cobalt Core members approving the test plan, and Cobalt states plainly that it "does not produce compliance attestation reports" and is "not a replacement for compliance-bound pentesting". Stingrai's Autonomous tier is built to be the audit artifact itself and ships a pentest report and attestation letter that supports SOC 2, HIPAA and PCI DSS programs, with automated retests included. Retest terms are a genuine Cobalt strength: unlimited on-demand retesting throughout the contract term. Stingrai includes retests in both tiers. Both firms hold a CREST Penetration Testing accreditation at company level. Cobalt publishes one dollar figure, an Autonomous Pentest at US$3,500 for tests completed before 31 December 2026, and quotes everything else. Stingrai publishes all of its list prices. Buy Cobalt when you run many small tests a year across a portfolio and want a marketplace of matched testers you can provision in a day. Buy Stingrai when the interesting bugs live in authorization and business logic inside one authenticated application, you want the same team and an AI agent working it together, and you want fixes to arrive as pull requests.

Cobalt publishes exactly one dollar figure across its entire pricing page: an Autonomous Pentest at US$3,500 per test, valid only for tests "initiated and completed before Dec 31st 2026", per the Cobalt pricing page. Everything else on that page, including the Standard, Premium and Enterprise tiers, is expressed in credits, where "A Cobalt Credit represents the equivalent of 8 hours of offensive security testing". Stingrai takes the opposite approach and publishes every list price it charges: US$3,000 for a one-time Autonomous Pentest, US$6,800 for a one-time Hybrid Pentest, and US$450 and US$1,275 per month for the same two tiers run continuously across a 12-month engagement, per the Stingrai pricing page.

That difference in commercial shape drives most of the rest of this comparison, and it is not the only one. This is a direct head-to-head, written from each company's own current pages, fetched and checked on 5 September 2026. Where a figure is not published, this post says "not published" rather than estimating it. If you are shopping the wider category instead of these two specifically, the Cobalt alternatives guide for 2026 ranks six platforms against the same criteria.

TL;DR: the decision in one table

If this is you

Pick

Why

You run 10 or more small tests a year across a portfolio and can forecast that volume

Cobalt

Credits are elastic within a contract year and a test starts in 1 to 3 business days

You need a fixed number you can put in a budget line today without a sales cycle

Stingrai

Every list price is published, including one-time engagement prices

You want continuous coverage of a whole application estate between compliance cycles

Cobalt

Autonomous Pentest is built for portfolio-wide coverage at 24-hour turnaround

The test IS the audit artifact for SOC 2, ISO 27001 or PCI DSS

Stingrai

Cobalt states its autonomous product "does not produce compliance attestation reports"

You want to retest as often as you like across a whole contract term

Cobalt

Unlimited on-demand retesting throughout the contract term

The bugs that matter are IDOR, business logic and broken authorization in one authenticated app

Stingrai

Snipe is built for those classes and penetration testers work the engagement alongside it

You want fixes to arrive as pull requests and vulnerable code blocked at merge

Stingrai

AutoFix pull requests and pull request gating; Cobalt does not publish an equivalent

You want a marketplace of testers matched to an unusual tech stack

Cobalt

500+ vetted security experts matched by the platform, average 11 years of experience

Quick comparison, with the source for every row

Every cell below traces to the URL in the final column. All rows last verified 5 September 2026.

Dimension

Cobalt

Stingrai

Source

Founded / HQ

2013, San Francisco, California

2021, Toronto, Ontario with a London, UK office

cobalt.io/about (no founding year stated on page; corroborated by company registries) / stingrai.io/pricing organization data

Positioning

"Continuous Offensive Security Testing"

Offensive security only: penetration testing, red teaming, adversary emulation, AI-augmented PTaaS

cobalt.io / stingrai.io

Who tests

Cobalt Core, "500+ vetted security experts" engaged as independent contractors and matched to your stack by the platform

Employed certified penetration testers working concurrently with Snipe on every engagement

Cobalt Core page / stingrai.io/pricing

Tester experience

"These seasoned professionals average 11 years of experience"

Team certifications include OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE, eWPTX

Cobalt Core page / stingrai.io

Tester continuity

Platform-matched per test; Cobalt states customers can request specific Cobalt Core members who have previously worked on their assets

The same employed team across engagements by default

Cobalt Core page / stingrai.io/ptaas

Commercial model

Annual credit packages; 1 credit = "the equivalent of 8 hours of offensive security testing"

Fixed price per scoped engagement, or a fixed monthly price on a 12-month engagement

cobalt.io/platform/pricing / stingrai.io/pricing

Published dollar figures

One: Autonomous Pentest at US$3,500 per test, for tests completed before 31 December 2026. Standard, Premium and Enterprise tier prices not published

US$3,000 one-time Autonomous, US$6,800 one-time Hybrid, US$450/month Autonomous, US$1,275/month Hybrid, Enterprise custom

cobalt.io/platform/pricing / stingrai.io/pricing

Scope covered by the published price

Not published per tier

One web application and its APIs

cobalt.io/platform/pricing / stingrai.io/pricing

Time to start

3 business days (Standard), 2 (Premium), 1 (Enterprise)

Scoped per engagement; Autonomous returns same-day results once launched

cobalt.io/platform/pricing / stingrai.io/pricing

Unused budget at year end

"Credits do not roll over into the next contract"; in-contract rollover is 6 months on Standard and 12 on Premium and Enterprise

No credit forecasting; a one-time engagement is priced once and a monthly program bills monthly

cobalt.io/platform/pricing / stingrai.io/pricing

Retesting

"Our PTaaS model provides unlimited on-demand retesting throughout your contract term"

Automated retests included on the Autonomous tier; retests included with the PTaaS platform

cobalt.io/platform/pricing / stingrai.io/pricing

Autonomous product

Cobalt Autonomous Pentest, launched July 2026, "A complete pentest is delivered in 24 hours"

Autonomous Pentest powered by Snipe, same-day results, sold as a one-time test or continuously

cobalt.io autonomous pentest / stingrai.io/snipe

Autonomous and compliance

"Cobalt Autonomous Pentest does not produce compliance attestation reports"

Autonomous tier delivers a pentest report and attestation letter supporting SOC 2, HIPAA and PCI DSS programs

cobalt.io autonomous pentest / stingrai.io/pricing

White-box source review

Secure code review is a separate service line

Snipe reads application source alongside black-box dynamic testing

cobalt.io/platform / stingrai.io/snipe

Fix automation

Not published

AutoFix pull requests generated for findings

cobalt.io/platform / stingrai.io/snipe

Merge protection

Not published

Pull request gating blocks vulnerable code from merging

cobalt.io/platform / stingrai.io/snipe

Outcome guarantee

Not published

"No High or Critical Finding = Don't Pay" on the Autonomous tier

cobalt.io/platform/pricing / stingrai.io/pricing

CREST at company level

Listed on the CREST Marketplace with a Penetration Testing accreditation, Europe region

CREST-accredited Penetration Testing service provider

marketplace.crest.org/cobalt-labs / stingrai.io

Integrations

"50+ integrations"; results stream to Jira, GitHub, ADO

PTaaS portal with Jira and Slack

cobalt.io / stingrai.io/pricing

Data residency and tester location controls

Not published

Toronto and London delivery; ask for specifics at scoping

cobalt.io/platform/pricing / stingrai.io/get-a-quote

Comparison chart of the Cobalt and Stingrai commercial models across six rows: how you buy, the unit of purchase, published dollar figures, unused budget at year end, retesting terms, and the autonomous testing offer, with each row marked as published or not published

Delivery model: a marketplace you draw down against, or a scoped engagement you price once

Cobalt's model is a provisioning engine. You buy a credit package for the contract year, scope a target in the portal, spend credits, and the platform matches testers from the Cobalt Core to your stack. The homepage promise is "Launch in hours", and the pricing page commits to a start within 3 business days on Standard, 2 on Premium and 1 on Enterprise. Support and planning are tiered the same way: email support on Standard, a named customer success manager with live collaboration on Premium and Enterprise, annual strategic planning on Premium and quarterly on Enterprise.

That is a genuinely good answer to a real problem. If your testing calendar is twelve small assessments spread across eight product teams, buying capacity once and drawing it down is far less procurement work than raising twelve purchase orders.

The cost of the model is forecasting. Credits are bought against a plan for the year, and Cobalt states that "Credits do not roll over into the next contract. To keep your momentum going, credits are specific to each contract year." In-contract rollover runs 6 months on Standard and 12 months on Premium and Enterprise, and Enterprise adds an "up to 10%" credit incentive. So elasticity exists inside the year and stops at the contract boundary. A mid-year acquisition, a new payments integration or a microservice nobody scoped in January all consume credits at 8 hours apiece.

Stingrai prices the engagement, not the capacity. A one-time Autonomous Pentest is US$3,000 and a one-time Hybrid Pentest is US$6,800, each covering one web application and its APIs. The same two tiers run continuously across a 12-month engagement at US$450 and US$1,275 per month. There is nothing to forecast and nothing to expire, and the number is on a public page before you speak to anyone. The trade in the other direction is real too: if your need is genuinely twelve unrelated targets, you are pricing twelve engagements or moving to the custom Enterprise tier, and Cobalt's package economics may land better.

Testing model: matched community contractors, or an employed team working with an agent

Cobalt's testers are the Cobalt Core, described on the homepage as "500+ vetted security experts". The Cobalt Core page describes a five-stage process covering sourcing, a technical assessment, interviews, third-party background checks and continuous quality assurance, with all testing conducted over Cobalt's secure VPN and work reviewed by leads and specialists. Members are engaged as independent professionals under NDAs and Terms of Engagement rather than employed, and Cobalt states they "average 11 years of experience", holding certifications including OSCP, OSWE, CREST and CRTO.

Continuity is available but buyer-driven. Cobalt states that while its platform automatically matches the best-vetted experts to your tech stack, customers can request specific Cobalt Core members who have previously worked on their assets. If tester continuity matters to you, ask for it by name at contract time rather than assuming it.

Stingrai's model is structurally different in two ways. First, the penetration testers are employed rather than matched per engagement, so the same people carry your authorization model from one cycle to the next by default. Second, Snipe, Stingrai's autonomous AI agent for web application penetration testing, runs on the same engagement at the same time as the humans rather than as a separate product. The penetration testers direct where Snipe hunts, extend the attack paths it opens and chain what it surfaces, and both contribute findings across every severity.

Snipe is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's own methodology, which is why it is pointed at the classes that generic automation structurally struggles with: IDOR, business logic flaws and broken authorization. It runs black-box dynamic testing and white-box source code review, generates AutoFix pull requests, and can run as a pull request gating check that blocks vulnerable code from merging. Cobalt sells secure code review as a separate service line and does not publish an equivalent to AutoFix pull requests or merge gating.

Autonomous offerings: closer than the marketing suggests, and Cobalt is candid about the limit

Both companies now sell an autonomous product, and this is the section where a fair comparison matters most.

Cobalt Autonomous Pentest launched in July 2026. Its product page describes a sequence of Crawl, Auth, Discovery, Planning, Exploit and Reporting phases, with dynamic surface mapping, automated profile creation, context-aware vulnerability generation and real-time proof of concept validation. "A complete pentest is delivered in 24 hours." Cobalt Core members "review and approve the AI-generated test plan", "approve or deny dynamic tool calls" during execution and "maintain authority to intervene". Findings stream to Jira, GitHub, ADO "and 50+ tools". The published price is US$3,500 per test for tests completed before 31 December 2026.

Cobalt then says something most vendors would not, and it deserves to be quoted rather than paraphrased: "Cobalt Autonomous Pentest does not produce compliance attestation reports." The page continues that "Most major frameworks, including PCI-DSS, SOC 2, ISO 27001, and HIPAA, require human-led pentesting with formal attestation", and that "Autonomous pentesting is designed for portfolio-wide coverage and risk reduction, not as a replacement for compliance-bound pentesting." Cobalt's recommendation is to run both: autonomous for coverage between compliance cycles, human-led for attestation.

That is an honest description of a deliberate product boundary, and it is the single most useful sentence on either company's site for a buyer trying to decide.

Stingrai's Autonomous Pentest draws the boundary in a different place. It is sold as the compliance artifact, not as coverage between artifacts: the pricing page lists the tier's output as a pentest report and attestation letter supporting SOC 2, HIPAA and PCI DSS programs, with same-day results, OWASP Top 10 coverage, business logic and authorization testing, role-based access testing, black, white or grey-box testing, automated retests and AutoFix pull requests. It also carries the only outcome guarantee either company publishes: "No High or Critical Finding = Don't Pay".

If you want more depth on how auditors treat AI-run testing, will an auditor accept an AI pentest in 2026 walks through what examiners actually ask for.

Reports, retesting and compliance evidence

Retesting is where compliance evidence is actually completed, and it is a straightforward Cobalt strength. Cobalt commits to "unlimited on-demand retesting throughout your contract term", which is the most generous published retest term of the two. If your remediation cycles are long and iterative, that matters.

Stingrai includes retests as well. The Autonomous tier lists automated retests, and the PTaaS platform is described as providing live findings with included retests. The practical difference is shape rather than presence: Cobalt gives you unlimited retests for as long as the contract runs, and Stingrai includes retesting inside the engagement price.

On the evidence itself, both firms are accredited at company level. Cobalt Labs appears on the CREST Marketplace with a Penetration Testing accreditation in the Europe region, alongside an ISO 27001 certification. Stingrai is a CREST-accredited Penetration Testing service provider, and its penetration testing supports client compliance programs for SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2. Verify any accreditation on the CREST Marketplace yourself rather than trusting a badge, because accreditations renew on a cycle. Our CREST-accredited penetration testing companies guide explains what each accreditation actually covers, and the pentest evidence auditors accept covers the artifact side.

What our own engagement data says about the choice

Stingrai published its platform data for the period October 2024 to August 2026 in The State of Penetration Testing 2026, and three of those numbers bear directly on this decision. Across 55 penetration tests producing 1,206 verified findings, 92.7% of tests surfaced at least one High or Critical issue, which is the argument against treating any single test as a formality. The verified-finding false-positive rate was 0.74%, nine records out of 1,216 logged, which is the number to benchmark any autonomous product against when a vendor tells you validation is handled. And Critical findings closed at a median of 10.5 days while High findings took far longer, which is why retest terms and pull-request-level remediation are worth pricing rather than treating as an afterthought.

Public pricing side by side

Cobalt

Stingrai

One-time autonomous test

US$3,500, tests completed before 31 December 2026

US$3,000

One-time test with human penetration testers

Not published

US$6,800 (Hybrid)

Continuous program, monthly

Not published

US$450 (Autonomous), US$1,275 (Hybrid)

Standard / Premium / Enterprise tier prices

Not published

Enterprise custom; Autonomous and Hybrid published

Unit of purchase

1 credit = the equivalent of 8 hours of offensive security testing

One web application and its APIs per engagement

Cost per credit

Not published

Not applicable

Retesting

Unlimited on-demand throughout the contract term

Included

Outcome guarantee

Not published

Autonomous tier only

Sources: Cobalt pricing and Stingrai pricing, both verified 5 September 2026. For engagement-level benchmarks beyond these two vendors, see the 2026 penetration testing cost guide.

Best fit by company profile

Cobalt fits you if:

  • You run a portfolio of applications and need broad, repeatable coverage rather than depth on one target. Cobalt Autonomous Pentest is explicitly designed to "Cover every application, not just the critical few".

  • Your annual testing volume is predictable enough to convert into a credit package.

  • You value provisioning speed above tester continuity, and a 1 to 3 business day start is worth more to you than the same testers every cycle.

  • Your remediation cycles are long, and unlimited retesting across the contract term is a material line item.

  • You have an unusual technology stack and want a marketplace to match specialists to it.

  • You are already standardized on Jira, GitHub or Azure DevOps and want findings streamed there with minimal setup.

Stingrai fits you if:

  • The test has to be the audit artifact. If a SOC 2, ISO 27001 or PCI DSS deadline is driving the purchase, buy the tier whose stated output is the report and attestation letter.

  • The bugs that would actually hurt you are authorization and business logic bugs inside one authenticated, multi-tenant application.

  • You want an AI agent and penetration testers on the same engagement at the same time, rather than an autonomous product and a human service sold separately.

  • You want remediation to arrive as a pull request, and vulnerable code blocked at merge rather than queued in a backlog.

  • You need a number for a budget line this week without opening a sales cycle.

  • You want a one-time annual penetration test and a continuous program available from the same team, priced the same way.

Neither is the answer if you need a US federal 3PAO, a FedRAMP-authorized testing platform, or a public bug bounty program operated by the same vendor. Those are different purchases with different vendors.

Frequently Asked Questions

How much does Cobalt cost in 2026?

Cobalt publishes one dollar figure: Autonomous Pentest at US$3,500 per test, and that price applies only to tests "initiated and completed before Dec 31st 2026". Every other tier, Standard, Premium and Enterprise, is priced in credits with no published dollar amount, so the cost of a credit and the cost of an annual package are both not published. All figures verified on the Cobalt pricing page on 5 September 2026.

What is a Cobalt credit and how much testing does it buy?

Cobalt defines it directly: "A Cobalt Credit represents the equivalent of 8 hours of offensive security testing", delivered through a combination of automation and human expertise. Credits are bought in annual packages and drawn down per test. Cobalt does not publish a dollar value per credit, so you cannot convert credits to cost without a quote.

Do Cobalt credits expire?

Within a contract year, unused credits roll over for 6 months on Standard and 12 months on Premium and Enterprise, and Enterprise adds an "up to 10%" credit incentive. Across contract years they do not: Cobalt states "Credits do not roll over into the next contract. To keep your momentum going, credits are specific to each contract year." Forecast accordingly.

Is Cobalt Autonomous Pentest good enough for a SOC 2 or PCI DSS audit?

Cobalt answers this on its own product page, and the answer is no by design: "Cobalt Autonomous Pentest does not produce compliance attestation reports." The page adds that "Most major frameworks, including PCI-DSS, SOC 2, ISO 27001, and HIPAA, require human-led pentesting with formal attestation" and recommends autonomous testing for coverage between compliance cycles rather than as a replacement for it. If the audit is the reason you are buying, scope a human-led engagement at Cobalt, or buy a tier elsewhere whose published output is the report and attestation letter.

Cobalt vs Stingrai: what is the actual difference?

Cobalt is a marketplace that provisions matched contractors fast and prices capacity in credits. Stingrai is a firm with employed certified penetration testers and a proprietary AI agent, Snipe, working the same engagement together, priced per scoped engagement at published rates. The practical differences are tester continuity, whether source code review and merge gating are inside the engagement, whether the autonomous product is positioned as the audit artifact, and whether you can see the price before you call.

What does Stingrai cost, and what does the price cover?

The Stingrai pricing page publishes an Autonomous Pentest from US$3,000 one-time or US$450 per month on a 12-month engagement, and a Hybrid Pentest with penetration testers at US$6,800 one-time or US$1,275 per month, with a custom Enterprise tier. Both published tiers cover one web application and its APIs. The Autonomous tier carries a "No High or Critical Finding = Don't Pay" guarantee. Larger scopes are quoted through get a quote.

Which one has better retest terms?

Cobalt, on published terms. Cobalt commits to "unlimited on-demand retesting throughout your contract term", which is the most generous retest language either company publishes. Stingrai includes retests inside the engagement, with automated retests listed on the Autonomous tier and included retests on the PTaaS platform. If iterative remediation over many months is your pattern, put Cobalt's retest term in the comparison explicitly.

Is Cobalt CREST accredited?

Yes. Cobalt Labs is listed on the CREST Marketplace with a Penetration Testing accreditation in the Europe region, plus an ISO 27001 certification, with 8 years of membership shown. Stingrai is also a CREST-accredited Penetration Testing service provider at firm level. Check both listings yourself before an audit, because accreditations renew on a cycle.

Does Cobalt generate fix pull requests or block vulnerable merges?

Not published. Cobalt streams findings into Jira, GitHub, Azure DevOps and 50-plus other tools, and sells secure code review as a separate service line, but no published Cobalt product page describes automatic generation of fix pull requests or a pull request gating check. Stingrai publishes both as part of what Snipe does. Ask Cobalt directly if this is a requirement rather than inferring it from the integration list.

Should I run both?

Often, yes, and Cobalt says so itself. A reasonable pattern is autonomous coverage across the portfolio between compliance cycles, plus one deep human-plus-AI engagement per year on the application that carries the most authorization complexity and the audit obligation. The continuous penetration testing versus PTaaS guide walks through how to split the budget.

Talk to Stingrai

If you already hold a Cobalt contract and want to know what a credit package is and is not covering on your most complex application, that is a short scoping conversation with a specific answer. Stingrai scopes against your real architecture: how many tenants, how many roles, where money moves, and what your auditor will ask for. Book a free scoping call, get a quote, or read the published pricing.

0 views

0

X

Related reading

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing
Web App SecurityNetwork Security

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing

Compare 8 BreachLock alternatives for 2026 on who tests, what the AI does, retest terms and published pricing, plus BreachLock vs Cobalt and Astra.

13 min read

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced
Web App SecurityNetwork Security

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced

Compare 8 Bugcrowd alternatives for penetration testing in 2026 on delivery model, compliance fit and published pricing, plus where Bugcrowd still wins.

14 min read

Best Coalfire Alternatives for Penetration Testing (2026): Compliance-Driven Pentests Compared
Web App SecurityNetwork Security

Best Coalfire Alternatives for Penetration Testing (2026): Compliance-Driven Pentests Compared

Compare 8 Coalfire alternatives for penetration testing in 2026 on accreditations, delivery model and published pricing, plus where Coalfire still wins.

14 min read

Contents

X