Penetration testing as a service
PTaaS platforms: 16 providers compared.
Every value comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not guess, and we do not rank.
Go to the tableSources: the provider pages themselves · Matproof sits in the table on the same terms · Read on 8 and 15 September 2026
Short answer
“PTaaS” covers five different ways of testing. 10 of 16 platforms publish a price.
Some platforms put in-house testers behind the portal (NetSPI, BreachLock, Software Secured). Some route work to a researcher community (HackerOne, Synack, Bugcrowd). Some combine automation with human assessment (Edgescan, ImmuniWeb). Some run AI agents first and hand off to people (Sprocket Security, Stingrai, Strobes). Matproof runs AI agents only. Decide which of those your auditor or customer will accept, then compare price and retest terms within that group.
The table
16 PTaaS platforms, every value sourced.
Rows are alphabetical after our own. The order is not a ranking. Each cell reflects pages on that provider's own website, and every source URL is listed further down.
| Platform | How it is delivered | Published price | Retest included | Frameworks named | Stated timing | Stated location |
|---|---|---|---|---|---|---|
| Matproofus | AI agent platform, self-serve | EUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote. | Yes | SOC 2, ISO 27001, DORA, NIS2 mapping | not published | Platform hosted in Germany, at Hetzner |
| Astra Security | Automated scan plus manual pentest | Pentest Auto USD 199 per month or USD 2,999 per year. Pentest Expert USD 5,999 per year. Enterprise from USD 9,999 per year. | Yes | SOC 2, ISO 27001, PCI DSS, HIPAA | Automated: “First report on the same day”. Manual pentest: “10-15 working days”. | not published |
| BreachLock | PTaaS with in-house certified pentesters, AI-accelerated | not published | Yes | SOC 2, PCI DSS, ISO 27001, HIPAA, HITRUST | “Launch penetration tests in 24–48 hours” | 1350 Avenue of the Americas, New York, NY 10019 (BreachLock Inc.) and Amsterdam (BreachLock NL B.V.) |
| Bugcrowd | Curated crowdsourced pentester teams on a platform | not published | Yes | PCI, HIPAA, GDPR, ISO 27001 | “Launch in less than 72 hours” | 300 California Street Suite 220, San Francisco, CA 94104 |
| Cobalt | PTaaS with a vetted tester pool | Autonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only. | Yes | not published | Findings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier. | not published |
| CYBRI | PTaaS with senior testers (Red Team members) on a platform | From USD 5,000 (Web Application package). Remediation testing is listed on the USD 9,500 and USD 20,000 packages. | Yes | HIPAA, PCI-DSS, SOC 2, ISO 27001, SEC | From 5 business days, covering testing, reporting and final delivery | 433 Broadway, 5th Floor, New York, NY 10013 |
| Edgescan | PTaaS, automation plus human assessment | not published | not published | PCI | not published | Unit 701 Northwest Business Park, Ballycoolin, Dublin 15, Ireland |
| HackerOne | PTaaS on a researcher community | not published | Yes | SOC 2, ISO 27001, GDPR, NIST CSF 2.0, NIST 800-53, FISMA, DORA | “Our team typically responds within 1 business day” | not published |
| ImmuniWeb | Self-service platform pairing automated scanning with senior pentesters | On-Demand packages: EUR 14,995, EUR 5,995, EUR 2,995 and EUR 995 per penetration test. | Yes | PCI DSS, SOC 2, ISO 27001, GDPR, PSD2, DORA, HIPAA | Testing begins within one business day of scoping | Quai de l’Ile 13, CH-1204 Geneva, Switzerland (headquarters) |
| NetSPI | Human-delivered PTaaS, in-house testers | not published | not published | not published | not published | not published |
| Red Sentry | Human-led pentesting delivered through a PTaaS platform | not published | Yes | SOC 2, ISO 27001, HIPAA, PCI DSS | Findings “in weeks, not months” | 3490 Piedmont Rd. NE, Suite 1350, Atlanta, GA 30305 |
| Software Secured | Human-led PTaaS subscription with full-time pentesters | From USD 21,400 (PTaaS) | Yes | SOC 2, ISO 27001 | Scheduling within 3 to 6 weeks; report within 48 to 72 hours of test completion | 301 Moodie Dr, Unit 108, Ottawa, ON K2H 9C4, Canada |
| Sprocket Security | Continuous penetration testing subscription: AI agents hand off to in-house human testers | USD 15,000 Starter Package, continuous testing on up to 20 external hosts. Billing period not stated. | Yes | not published | “1–2 weeks to first validated findings” | 821 E Washington Ave, Suite 402, Madison, WI 53703 |
| Stingrai | Autonomous agent alone, or together with human pentesters, on a PTaaS platform | USD 3,000 one-time (Autonomous Pentest). USD 6,800 one-time (Hybrid Pentest). One web app plus its APIs. | Yes | SOC 2, HIPAA, PCI DSS, ISO 27001 | Autonomous Pentest: “Same-day results” | 1 Adelaide Street East, #3001, Toronto, Ontario M5C 2V9, Canada (HQ) |
| Strobes | Certified pentesters and AI agents on the Strobes platform | USD 4,800 PTaaS Standard (5 credits at USD 960 per credit, 1 target) | Yes | PCI DSS, SOC 2, ISO 27001, HIPAA, GDPR | Engagements begin in under 48 hours; final report within 10 business days (Standard) | 5700 Tennyson Parkway, Suite 372, Plano, Texas 75024 (business office) |
| Synack | Vetted researcher team, on demand | AI Sara Pentest from USD 4,181. Standard Pentest from USD 10,283. Synack14 Pentest from USD 27,120. | not published | FedRAMP moderate designation | “Launch tests in days, not weeks” | not published |
The Matproof, Astra Security, Cobalt, Edgescan, HackerOne, NetSPI and Synack rows were read on 8 September 2026; all other rows, and Synack's price, on 15 September 2026, each from the provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation, or that its report is accepted by any auditor. “Stated location” is whatever the provider states and is not normalised. Row order carries no judgement.
- Matproof: “3 full Sentinel pentests per month … Remediation-diff metric across re-tests” https://matproof.com/pricing
- Astra Security: “Pentest report for SOC2, ISO27001, HIPAA etc. compliances” https://www.getastra.com/pricing
- BreachLock: “Every BreachLock pentest is conducted by in-house certified pentesters across the U.S., Europe, and Asia carrying certifications including CREST, OSCP, OSCE.” https://www.breachlock.com/pricing/penetration-testing-pricing/
- Bugcrowd: “Our platform activates trusted, expert penetration testers for your needs from an elastic bench to find more critical vulns than traditional testing.” https://www.bugcrowd.com/products/pen-test-as-a-service/
- Cobalt: “unlimited on-demand retesting throughout your contract term” https://www.cobalt.io/pricing
- CYBRI: “CYBRI Pen Tests are on-demand hacker-powered penetration tests performed by one or two Red Team members.” https://cybri.com/pricing/
- Edgescan: “Hybrid solution that combines the breadth of automation with the depth of human assessment” https://www.edgescan.com/pricing/
- HackerOne: “HackerOne provides retesting to confirm that the fixes have been correctly implemented” https://www.hackerone.com/product/pentest
- ImmuniWeb: “ImmuniWeb® On-Demand delivers PTaaS for your web apps, mobile apps, APIs and cloud from one self-service platform — pairing machine-speed scanning with senior pentesters, a live dashboard and a contractual zero false positives SLA.” https://www.immuniweb.com/products/ondemand/
- NetSPI: “human-delivered, contextualized pentesting services” with “350+ in-house pentesters” https://www.netspi.com/security-testing/penetration-testing-as-a-service/
- Red Sentry: “Human-led testing, a dedicated project manager, findings delivered live, audit-ready reports mapped to SOC 2, HIPAA, and PCI DSS with a letter of attestation, a free remediation re-test, and ongoing platform access.” https://redsentry.com/pentest-cost
- Software Secured: “Frequent, human led pentesting aligned to releases; we prove exploitability, verify fixes through unlimited retesting, and deliver stakeholder-ready evidence that accelerates audits and approvals.” https://www.softwaresecured.com/service/penetration-testing-as-a-service
- Sprocket Security: “Our AI agents run reconnaissance, discovery, and exploitation — then hand off to expert human testers who verify impact and drive findings to closure.” https://www.sprocketsecurity.com/pricing
- Stingrai: “Every reported vulnerability is verified by our penetration testers, who work alongside Snipe throughout the engagement.” https://www.stingrai.io/pricing
- Strobes: “CREST/OSCP testers and AI agents work in parallel.” https://strobes.co/pricing/
- Synack: “Synack14 provides a two-week process for pentesting while Synack90 and Synack365 provide 90-day and year-round options respectively” https://www.synack.com/platform/pricing/
Fit
Who each platform is the right answer for.
One line per platform, written from what the provider publishes about its own service.
| Platform | The right answer when |
|---|---|
| Matproof | Teams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone. |
| Astra Security | Buyers who want one supplier for an automated scanner and a human pentest, with both prices on the page. |
| BreachLock | Teams that want in-house testers on a platform for one-time, periodic or continuous pentests. |
| Bugcrowd | Organizations that want pentests from curated crowd testers, with bug bounty available on the same platform. |
| Cobalt | Buyers who want a named human tester pool and can accept a quote for everything above the entry test. |
| CYBRI | Companies that want a fixed-price, manual-first pentest of a web app, API, cloud or network. |
| Edgescan | EU buyers who want the supplier itself inside the EU and are buying a programme rather than a single test. |
| HackerOne | Buyers who already run or plan a bug bounty and want the pentest in the same platform. |
| ImmuniWeb | Teams that want to buy a fixed-price web application pentest online and start within one business day. |
| NetSPI | Large estates that want one supplier across network, cloud and application testing, on a quote. |
| Red Sentry | Teams that test more than once a year and want live findings and a free remediation re-test. |
| Software Secured | Software teams that ship often and want recurring manual pentests aligned to releases. |
| Sprocket Security | Organizations that want year-round testing of their external hosts on a subscription. |
| Stingrai | Teams that need a pentest of one web app and its APIs at a published fixed price, autonomous or with human testers. |
| Strobes | Teams that want credit-based pentests on the same platform they use for exposure management. |
| Synack | Buyers with a US public sector requirement, or who want a continuous engagement rather than one test. |
Method
How we compared.
For every platform we read its own website: the PTaaS or pentest product page, the pricing page where one exists, and the contact or company page for the location. Where a price only appears after clicking a tab, we read it in a browser.
A script compared each quoted value against the saved page text. We used no review sites, no analyst reports and nothing from memory.
Matproof publishes this page and sells one of the products in it. Our row carries sources like every other row, and it says what does not flatter us: there is no human tester, prices are in EUR, and we publish no turnaround time.
All sources
- Matproof
https://matproof.com/pricinghttps://matproof.com/trust - Astra Security
https://www.getastra.com/pricing - BreachLock
https://www.breachlock.com/pricing/penetration-testing-pricing/https://www.breachlock.com/products/ptaas/ - Bugcrowd
https://www.bugcrowd.com/products/pen-test-as-a-service/https://www.bugcrowd.com/about/contact/ - Cobalt
https://www.cobalt.io/pricing - CYBRI
https://cybri.com/pricing/https://cybri.com/contact-us/ - Edgescan
https://www.edgescan.com/pricing/ - HackerOne
https://www.hackerone.com/product/pentest - ImmuniWeb
https://www.immuniweb.com/products/ondemand/https://www.immuniweb.com/use-cases/penetration-testing-as-a-service-ptaas/https://www.immuniweb.com/company/contacts/ - NetSPI
https://www.netspi.com/security-testing/penetration-testing-as-a-service/ - Red Sentry
https://redsentry.com/pentest-costhttps://redsentry.com/ptaashttps://redsentry.com/https://redsentry.com/terms-and-conditions - Software Secured
https://www.softwaresecured.com/service/penetration-testing-as-a-servicehttps://www.softwaresecured.com/contact-us - Sprocket Security
https://www.sprocketsecurity.com/pricinghttps://www.sprocketsecurity.com/solutions/continuous-penetration-testinghttps://www.sprocketsecurity.com/agentshttps://www.sprocketsecurity.com/company/contact - Stingrai
https://www.stingrai.io/pricinghttps://www.stingrai.io/contact-us - Strobes
https://strobes.co/pricing/https://strobes.co/solutions/pentesting-as-a-service/https://strobes.co/contact/ - Synack
https://www.synack.com/platform/pricing/https://www.synack.com/platform/
What we could not source, and how to read some cells
- Strobes: its PTaaS tab says unlimited re-testing is included, while its Standard package lists one round of free re-testing after fixes. Both statements are on its pricing page.
- ImmuniWeb: its PTaaS page says free unlimited retesting; its On-Demand page limits retests to a window after the report. The four On-Demand prices are shown without tier names because we could not confirm which price sits under which name.
- CYBRI: remediation testing is listed on the USD 9,500 and USD 20,000 packages, not on the USD 5,000 package.
- Sprocket Security: the pricing page gives no billing period for USD 15,000 and names no compliance framework. Sprocket calls its service continuous penetration testing.
- Bugcrowd: SOC 2 appears only in a general FAQ answer about pentesting, so it is not in the frameworks cell. Its agentic product was in early access and is not scored.
- BreachLock, Strobes and ImmuniWeb: BreachLock and Strobes name no headquarters, so we print the office addresses their sites show.
- Price is unpublished for BreachLock, Bugcrowd, Edgescan, HackerOne, NetSPI, Red Sentry and Synack on the pages we read.
FAQ
Common questions about PTaaS platforms
What is PTaaS?
Penetration testing as a service puts a penetration test behind a platform. You start tests on demand, see findings as they are confirmed rather than in a final PDF, and usually request retests from the same place. The label covers very different delivery models, which is why the “How it is delivered” column matters more than the name: in-house testers (NetSPI, BreachLock, Software Secured), a vetted researcher community (HackerOne, Synack, Bugcrowd), automation plus human assessment (Edgescan, ImmuniWeb), AI agents handing off to people (Sprocket Security, Stingrai, Strobes), and AI agents only (Matproof).
How much does PTaaS cost?
10 of the 16 platforms here publish a price: Matproof, Astra Security, Cobalt, CYBRI, ImmuniWeb, Software Secured, Sprocket Security, Stingrai, Strobes and Synack. Published entry points include ImmuniWeb from EUR 995 per test, Stingrai USD 3,000 for an autonomous test, Strobes USD 4,800 for a standard credit pack, CYBRI from USD 5,000, Sprocket Security USD 15,000 for its starter package and Software Secured from USD 21,400. Matproof publishes EUR 149 per run and EUR 299 per month. The rest quote after a call.
Is the retest included in PTaaS?
On the pages we read, Matproof, Astra Security, BreachLock, Bugcrowd, Cobalt, CYBRI, HackerOne, ImmuniWeb, Red Sentry, Software Secured, Sprocket Security, Stingrai and Strobes state that a retest after remediation is included in some form. The terms differ: CYBRI lists remediation testing on its larger packages, Bugcrowd states 12 months of retesting with one report update, and ImmuniWeb's on-demand product limits retesting to a window after the report. Get the retest terms in writing before you sign.
PTaaS or a traditional penetration test?
A traditional test is a project with a fixed window and a report at the end. PTaaS is better when you ship often, need evidence across a SOC 2 Type II period, or want findings in your ticketing tool as they land. A traditional engagement is better when a contract names a specific firm, method or signed report. Many teams run both: one scoped engagement a year and a platform in between.
Does PTaaS satisfy SOC 2, PCI DSS or ISO 27001?
The platform does not decide that; your auditor or QSA does. PCI DSS v4.0 requirement 11.4 asks for a qualified internal resource or qualified external third party with organizational independence, at least once every 12 months and after significant change. It does not say how the test is delivered. Check with your assessor before you rely on any report, ours included.
Next step
See your own attack surface first.
The free scan checks your public surface without an account and returns a report you can take to any platform above, including the ones that are not us.
Run the free scan