# Cobalt vs YesWeHack

| Attribute | Cobalt | YesWeHack |
|---|---|---|
| **Vioscale score** | 28.2 (26% (low)) | 34.5 (29% (low)) |
| deployment.options | `{"cloud":true}` | `{"cloud":true}` |
| description.long | Cobalt provides penetration testing and vulnerability assessment services through a SaaS platform. Services include automated and manual security testing for web applications, APIs, networks, and cloud infrastructure, with findings delivered in real-time and integrated with development workflows. | A cloud-based platform that helps organizations discover and fix vulnerabilities across their entire internet-facing attack surface through automated penetration testing, community-powered bug bounty programs, and vulnerability disclosure policies, with compliance-ready reporting and security workflow integration. |
| integrations.count | 50 | 13 |
| integrations.list | `[{"name":"Slack"},{"name":"Jira"},{"name":"GitHub"},{"name":"ServiceNow"},{"name":"Microsoft Teams"}]` | `[{"name":"Jira"},{"name":"ServiceNow"},{"name":"GitHub"},{"name":"GitLab"},{"name":"Azure DevOps"},{"name":"UBIKA"},{"name":"Mindflow"},{"name":"Hackuity"},{"name":"BlinkOps"},{"name":"AWS Marketplace"},{"name":"Burp Suite"},{"name":"Firefox"}]` |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"hqCountry":"FR","primaryMarkets":["FR","GB","US","SE","AE","CA"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"web":true}` |
| pricing | `{"type":"subscription","plans":[{"free":false,"name":"Autonomous Pentest","summary":"$3,500 per test","features":["Web application testing","Findings in 24 hours with proof of exploit and remediation guidance","Cobalt Core pentester direction on every engagement","Plan review, in-flight oversight, scope enforcement","Results delivered in Cobalt Offensive Security Platform","Integrations with Jira, GitHub, Slack, and 50+ tools","Structured report"],"commitment":"annual","components":[{"kind":"one_time","amount":3500,"currency":"USD"}],"description":"AI-powered penetration testing with expert oversight, findings within 24 hours","contactSales":false}],"summary":"From $3,500 per test; annual credit-based packages available","currency":"USD","freeTier":false,"sourceUrl":"https://www.cobalt.io/platform/pricing","retrievedAt":"2026-08-18T22:04:04.182Z","startingPrice":{"amount":3500,"currency":"USD"},"billingPeriods":["year"]}` | `{"type":"usage","sourceUrl":"https://www.yeswehack.com","retrievedAt":"2026-08-18T22:04:21.224Z"}` |
| pricing.free_tier | no | - |
| pricing.model | commercial | commercial |
| pricing.price_level | high | unknown |
| pricing.starting_price | `{"amount":3500,"currency":"USD"}` | - |
| pricing.transparent | no | no |
| security.disclosure_policy | - | yes |
| security.gdpr | - | yes |
| security.iso27001 | - | yes |
| security.soc2 | - | yes |

## Capabilities (Bug Bounty)

| Capability | Cobalt | YesWeHack |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Public bug bounty programs | - | - |
| Private invite only programs | - | - |
| Vulnerability disclosure programs | - | - |
| Managed bug triage deduplication | - | - |
| Platform managed payouts | - | - |
| Cvss scoring assistance | - | - |
| Jira linear integration | - | - |
| Slack teams alerting | - | - |
| Continuous attack surface discovery | - | - |
| SOC2 type ii | - | - |
| ISO 27001 | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T14:39:48.989Z. "-" = undocumented, not absent.*
