# Cobalt vs HackerOne

| Attribute | Cobalt | HackerOne |
|---|---|---|
| **Vioscale score** | 28.2 (26% (low)) | 5.6 (15% (low)) |
| deployment.options | `{"cloud":true}` | `{"cloud":true}` |
| description.long | Cobalt provides penetration testing and vulnerability assessment services through a SaaS platform. Services include automated and manual security testing for web applications, APIs, networks, and cloud infrastructure, with findings delivered in real-time and integrated with development workflows. | HackerOne provides an integrated system for identifying and fixing critical vulnerabilities across an organization's attack surface. It combines automated detection, expert validation, and prioritization powered by an elite community of security researchers to close the gap between vulnerability discovery and remediation. |
| integrations.count | 50 | 3 |
| integrations.list | `[{"name":"Slack"},{"name":"Jira"},{"name":"GitHub"},{"name":"ServiceNow"},{"name":"Microsoft Teams"}]` | `[{"name":"Slack"},{"name":"JIRA"},{"name":"GitHub"}]` |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"web":true}` |
| pricing | `{"type":"subscription","plans":[{"free":false,"name":"Autonomous Pentest","summary":"$3,500 per test","features":["Web application testing","Findings in 24 hours with proof of exploit and remediation guidance","Cobalt Core pentester direction on every engagement","Plan review, in-flight oversight, scope enforcement","Results delivered in Cobalt Offensive Security Platform","Integrations with Jira, GitHub, Slack, and 50+ tools","Structured report"],"commitment":"annual","components":[{"kind":"one_time","amount":3500,"currency":"USD"}],"description":"AI-powered penetration testing with expert oversight, findings within 24 hours","contactSales":false}],"summary":"From $3,500 per test; annual credit-based packages available","currency":"USD","freeTier":false,"sourceUrl":"https://www.cobalt.io/platform/pricing","retrievedAt":"2026-08-18T22:04:04.182Z","startingPrice":{"amount":3500,"currency":"USD"},"billingPeriods":["year"]}` | `{"type":"quote","plans":[{"free":false,"name":"Professional","contactSales":true},{"free":false,"name":"Enterprise","contactSales":true}],"summary":"Professional and Enterprise tiers available; contact sales for pricing.","sourceUrl":"https://www.hackerone.com","retrievedAt":"2026-08-18T22:05:18.595Z"}` |
| pricing.free_tier | no | - |
| pricing.model | commercial | quote |
| pricing.price_level | high | unknown |
| pricing.starting_price | `{"amount":3500,"currency":"USD"}` | - |
| pricing.transparent | no | no |
| security.disclosure_policy | - | yes |

## Capabilities (Bug Bounty)

| Capability | Cobalt | HackerOne |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Public bug bounty programs | - | - |
| Private invite only programs | - | - |
| Vulnerability disclosure programs | - | - |
| Managed bug triage deduplication | - | - |
| Platform managed payouts | - | - |
| Cvss scoring assistance | - | - |
| Jira linear integration | - | - |
| Slack teams alerting | - | - |
| Continuous attack surface discovery | - | - |
| SOC2 type ii | - | - |
| ISO 27001 | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T17:34:30.450Z. "-" = undocumented, not absent.*
