Cobalt
How does Fluid Attacks’ solution compare to Cobalt’s? The following comparison table enables you to discern the performance of both providers across various attributes essential for meeting your company’s cybersecurity needs. To better understand each attribute, read their descriptions in the dedicated page . Organization
| Attribute | Essential | Advanced | Cobalt |
| Focus | Native ASPM with Built-In Scanners | AI-Powered PTaaS on top of Native ASPM with Built-In Scanners | DAST and PTaaS |
| Extras | None | None | Bug bounty , device hardening , IoT testing , LLM pentest , network pentest service , red team and social engineering |
| Employees | 130 | Same | 492 |
| Reputation | 9.82 from 60 reviews over 6 years on Gartner and Clutch | Same | 9.28 from 129 reviews over 6 years on Capterra , G2 and Gartner |
| Followers | 18K based on the following: Facebook , Instagram , LinkedIn , X and YouTube | Same | 43K based on the following: Instagram , LinkedIn , X and YouTube |
| Research Firms | None | None | GigaOM and Info-Tech Research Group |
| Founded | 2001 | Same | 2013 |
| Funding | Bootstrapped | Same | $37M USDÂ in 7 rounds from 22 investors |
| Revenue | 5M to 10M | Same | 10M to 125.1M |
| CVE | 257 CVEs reported to MITRE , ranked in the top 10 CVE labs worldwide | Same | 0 CVEs reported to MITRE |
| Compliance | SOC 2 Type II and SOC 3 | Same | ISO/IEC 27001 , SOC 2 Type I and SOC 2 Type II |
| Documentation | Yes | Yes | Yes |
| Visits | 26K per month. Top 3 : 36% MY, 33% CO, 5% IN and others 26% | Same | 120K per month. Top 3 : 33% IN, 19% US, 7% EG and others 41% |
| Authority | 31 out of 100 | Same | 43 out of 100 |
| Distribution | Direct or with any of its 14 partners | Same | Direct or with any of its partners |
| Marketplaces | AWS | Same | None |
| Freemium | No | No | No |
| Free trial | 21-day free trial | PoV | No |
| Demo | Yes | Yes | Yes |
| Pricing | Contact sales and marketplace | Contact sales | Contact sales |
| Pricing drivers | Groups | Authors | Credits |
Service
| Attribute | Essential | Advanced | Cobalt |
| PTaaS | No | Yes | MPT and PTaaS |
| Reverse engineering | No | Yes | Yes |
| Secure code review | No | Yes | Yes |
| Pivoting | No | Yes | No information available |
| Exploitation | No | Yes | Yes |
| Zero-day vulnerabilities | None | Continuous zero-day vulnerability research | None |
| SLA | Availability | Accuracy , availability and response | No information available |
| Accreditations | CNA and Penetration Testing by CREST | Same | Penetration Testing by CREST |
| Hacker certifications | Not applicable | 202 from 59 different types | 238 from 32 different types |
| Type of contract | Employee | Same | Employee or freelance |
| Standards | Some requirements from 65 standards , 18 in common and 47 additional | All requirements from the same standards | 22 standards , 18 in common and 4 additional |
| Detection method | Automated tools | Automated tools , AI and human intelligence | Automated tools and human intelligence |
| Remediation | 5Â , 1 in common and 4 additional | Same, plus 1Â | 1Â in common |
| Outputs | 5Â , 2 in common and 3 additional | Same, plus 2Â | 3 formats, 2 in common and 1 additional |
Product
| Attribute | Essential | Advanced | Cobalt |
| ASPM | Yes | Yes | No |
| IDE | 4 functionalities | Same , plus 1 functionality | No |
| CLI | Yes | Yes | No |
| CI/CD | Break the build | Same | Does not break the build |
| SCA | 18 package managers | Same | No |
| Reachability | 12 languages | Same | No |
| SBOM | 18 package managers | Same | No |
| Containers | 4 distributions | Same | No |
| Source SAST (languages) | 18 | Same | No |
| Source SAST (frameworks) | 22 | Same | No |
| Binary SAST | 1 type of binary | Same , plus 2 types of binaries | No |
| DAST | 10 attack surfaces | Same | 6 attack surfaces , all in common |
| IAST | No | No | No |
| CSPM | Yes | Yes | No |
| Secrets | 15 secrets types | Same , plus verify other attack vectors and secrets exploitability | No |
| AI | 3 functions | Same | No |
| Open source | MPL-2.0 license . Totally equivalent to the paid version | Not applicable | No |
| Deployment | SaaS | Same | SaaS |
| Regions | US | Same | No information available |
| Status | Yes | Yes | No |
| Incidents | 6 per year | Same | No information available |
Integrations
| Attribute | Essential | Advanced | Cobalt |
| SCM | 4 | Same | None |
| Binary repositories | None | None | None |
| Ticketing | 3 , 2 in common and 1 additional | Same | 7 , 2 in common and 5 additional |
| ChatOps | None | None | 2Â |
| IDE | 2 | Same | None |
| CI/CD | 20 | Same | None |
| SCA | Native scanner | Same | None |
| Container | Native scanner | Same | None |
| SAST | Native scanner | Same | None |
| DAST | Native scanner | Same | Native scanner |
| IAST | None | None | None |
| Cloud | 3 | Same | None |
| CSPM | Native scanner | Same | None |
| Secrets | Native scanner | Same | None |
| Compliance | None | None | 2Â |
References were last checked on Apr 11, 2025.
More like Cobalt
Free trialSearch for vulnerabilities in your apps for free with Fluid Attacks’ automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan . If you prefer the Advanced plan, which includes the expertise of Fluid Attacks’ hacking team, fill out this contact form .