SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

Penetration testing as a service

PTaaS platforms: 16 providers compared.

Every value comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not guess, and we do not rank.

Go to the table

Sources: the provider pages themselves · Matproof sits in the table on the same terms · Read on 8 and 15 September 2026

Short answer

“PTaaS” covers five different ways of testing. 10 of 16 platforms publish a price.

Some platforms put in-house testers behind the portal (NetSPI, BreachLock, Software Secured). Some route work to a researcher community (HackerOne, Synack, Bugcrowd). Some combine automation with human assessment (Edgescan, ImmuniWeb). Some run AI agents first and hand off to people (Sprocket Security, Stingrai, Strobes). Matproof runs AI agents only. Decide which of those your auditor or customer will accept, then compare price and retest terms within that group.

The table

16 PTaaS platforms, every value sourced.

Rows are alphabetical after our own. The order is not a ranking. Each cell reflects pages on that provider's own website, and every source URL is listed further down.

PlatformHow it is deliveredPublished priceRetest includedFrameworks namedStated timingStated location
MatproofusAI agent platform, self-serveEUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote.YesSOC 2, ISO 27001, DORA, NIS2 mappingnot publishedPlatform hosted in Germany, at Hetzner
Astra SecurityAutomated scan plus manual pentestPentest Auto USD 199 per month or USD 2,999 per year. Pentest Expert USD 5,999 per year. Enterprise from USD 9,999 per year.YesSOC 2, ISO 27001, PCI DSS, HIPAAAutomated: “First report on the same day”. Manual pentest: “10-15 working days”.not published
BreachLockPTaaS with in-house certified pentesters, AI-acceleratednot publishedYesSOC 2, PCI DSS, ISO 27001, HIPAA, HITRUST“Launch penetration tests in 24–48 hours”1350 Avenue of the Americas, New York, NY 10019 (BreachLock Inc.) and Amsterdam (BreachLock NL B.V.)
BugcrowdCurated crowdsourced pentester teams on a platformnot publishedYesPCI, HIPAA, GDPR, ISO 27001“Launch in less than 72 hours”300 California Street Suite 220, San Francisco, CA 94104
CobaltPTaaS with a vetted tester poolAutonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only.Yesnot publishedFindings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier.not published
CYBRIPTaaS with senior testers (Red Team members) on a platformFrom USD 5,000 (Web Application package). Remediation testing is listed on the USD 9,500 and USD 20,000 packages.YesHIPAA, PCI-DSS, SOC 2, ISO 27001, SECFrom 5 business days, covering testing, reporting and final delivery433 Broadway, 5th Floor, New York, NY 10013
EdgescanPTaaS, automation plus human assessmentnot publishednot publishedPCInot publishedUnit 701 Northwest Business Park, Ballycoolin, Dublin 15, Ireland
HackerOnePTaaS on a researcher communitynot publishedYesSOC 2, ISO 27001, GDPR, NIST CSF 2.0, NIST 800-53, FISMA, DORA“Our team typically responds within 1 business day”not published
ImmuniWebSelf-service platform pairing automated scanning with senior pentestersOn-Demand packages: EUR 14,995, EUR 5,995, EUR 2,995 and EUR 995 per penetration test.YesPCI DSS, SOC 2, ISO 27001, GDPR, PSD2, DORA, HIPAATesting begins within one business day of scopingQuai de l’Ile 13, CH-1204 Geneva, Switzerland (headquarters)
NetSPIHuman-delivered PTaaS, in-house testersnot publishednot publishednot publishednot publishednot published
Red SentryHuman-led pentesting delivered through a PTaaS platformnot publishedYesSOC 2, ISO 27001, HIPAA, PCI DSSFindings “in weeks, not months”3490 Piedmont Rd. NE, Suite 1350, Atlanta, GA 30305
Software SecuredHuman-led PTaaS subscription with full-time pentestersFrom USD 21,400 (PTaaS)YesSOC 2, ISO 27001Scheduling within 3 to 6 weeks; report within 48 to 72 hours of test completion301 Moodie Dr, Unit 108, Ottawa, ON K2H 9C4, Canada
Sprocket SecurityContinuous penetration testing subscription: AI agents hand off to in-house human testersUSD 15,000 Starter Package, continuous testing on up to 20 external hosts. Billing period not stated.Yesnot published“1–2 weeks to first validated findings”821 E Washington Ave, Suite 402, Madison, WI 53703
StingraiAutonomous agent alone, or together with human pentesters, on a PTaaS platformUSD 3,000 one-time (Autonomous Pentest). USD 6,800 one-time (Hybrid Pentest). One web app plus its APIs.YesSOC 2, HIPAA, PCI DSS, ISO 27001Autonomous Pentest: “Same-day results”1 Adelaide Street East, #3001, Toronto, Ontario M5C 2V9, Canada (HQ)
StrobesCertified pentesters and AI agents on the Strobes platformUSD 4,800 PTaaS Standard (5 credits at USD 960 per credit, 1 target)YesPCI DSS, SOC 2, ISO 27001, HIPAA, GDPREngagements begin in under 48 hours; final report within 10 business days (Standard)5700 Tennyson Parkway, Suite 372, Plano, Texas 75024 (business office)
SynackVetted researcher team, on demandAI Sara Pentest from USD 4,181. Standard Pentest from USD 10,283. Synack14 Pentest from USD 27,120.not publishedFedRAMP moderate designation“Launch tests in days, not weeks”not published

The Matproof, Astra Security, Cobalt, Edgescan, HackerOne, NetSPI and Synack rows were read on 8 September 2026; all other rows, and Synack's price, on 15 September 2026, each from the provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation, or that its report is accepted by any auditor. “Stated location” is whatever the provider states and is not normalised. Row order carries no judgement.

Fit

Who each platform is the right answer for.

One line per platform, written from what the provider publishes about its own service.

PlatformThe right answer when
MatproofTeams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone.
Astra SecurityBuyers who want one supplier for an automated scanner and a human pentest, with both prices on the page.
BreachLockTeams that want in-house testers on a platform for one-time, periodic or continuous pentests.
BugcrowdOrganizations that want pentests from curated crowd testers, with bug bounty available on the same platform.
CobaltBuyers who want a named human tester pool and can accept a quote for everything above the entry test.
CYBRICompanies that want a fixed-price, manual-first pentest of a web app, API, cloud or network.
EdgescanEU buyers who want the supplier itself inside the EU and are buying a programme rather than a single test.
HackerOneBuyers who already run or plan a bug bounty and want the pentest in the same platform.
ImmuniWebTeams that want to buy a fixed-price web application pentest online and start within one business day.
NetSPILarge estates that want one supplier across network, cloud and application testing, on a quote.
Red SentryTeams that test more than once a year and want live findings and a free remediation re-test.
Software SecuredSoftware teams that ship often and want recurring manual pentests aligned to releases.
Sprocket SecurityOrganizations that want year-round testing of their external hosts on a subscription.
StingraiTeams that need a pentest of one web app and its APIs at a published fixed price, autonomous or with human testers.
StrobesTeams that want credit-based pentests on the same platform they use for exposure management.
SynackBuyers with a US public sector requirement, or who want a continuous engagement rather than one test.

Method

How we compared.

For every platform we read its own website: the PTaaS or pentest product page, the pricing page where one exists, and the contact or company page for the location. Where a price only appears after clicking a tab, we read it in a browser.

A script compared each quoted value against the saved page text. We used no review sites, no analyst reports and nothing from memory.

Matproof publishes this page and sells one of the products in it. Our row carries sources like every other row, and it says what does not flatter us: there is no human tester, prices are in EUR, and we publish no turnaround time.

All sources

What we could not source, and how to read some cells

  • Strobes: its PTaaS tab says unlimited re-testing is included, while its Standard package lists one round of free re-testing after fixes. Both statements are on its pricing page.
  • ImmuniWeb: its PTaaS page says free unlimited retesting; its On-Demand page limits retests to a window after the report. The four On-Demand prices are shown without tier names because we could not confirm which price sits under which name.
  • CYBRI: remediation testing is listed on the USD 9,500 and USD 20,000 packages, not on the USD 5,000 package.
  • Sprocket Security: the pricing page gives no billing period for USD 15,000 and names no compliance framework. Sprocket calls its service continuous penetration testing.
  • Bugcrowd: SOC 2 appears only in a general FAQ answer about pentesting, so it is not in the frameworks cell. Its agentic product was in early access and is not scored.
  • BreachLock, Strobes and ImmuniWeb: BreachLock and Strobes name no headquarters, so we print the office addresses their sites show.
  • Price is unpublished for BreachLock, Bugcrowd, Edgescan, HackerOne, NetSPI, Red Sentry and Synack on the pages we read.

FAQ

Common questions about PTaaS platforms

What is PTaaS?

Penetration testing as a service puts a penetration test behind a platform. You start tests on demand, see findings as they are confirmed rather than in a final PDF, and usually request retests from the same place. The label covers very different delivery models, which is why the “How it is delivered” column matters more than the name: in-house testers (NetSPI, BreachLock, Software Secured), a vetted researcher community (HackerOne, Synack, Bugcrowd), automation plus human assessment (Edgescan, ImmuniWeb), AI agents handing off to people (Sprocket Security, Stingrai, Strobes), and AI agents only (Matproof).

How much does PTaaS cost?

10 of the 16 platforms here publish a price: Matproof, Astra Security, Cobalt, CYBRI, ImmuniWeb, Software Secured, Sprocket Security, Stingrai, Strobes and Synack. Published entry points include ImmuniWeb from EUR 995 per test, Stingrai USD 3,000 for an autonomous test, Strobes USD 4,800 for a standard credit pack, CYBRI from USD 5,000, Sprocket Security USD 15,000 for its starter package and Software Secured from USD 21,400. Matproof publishes EUR 149 per run and EUR 299 per month. The rest quote after a call.

Is the retest included in PTaaS?

On the pages we read, Matproof, Astra Security, BreachLock, Bugcrowd, Cobalt, CYBRI, HackerOne, ImmuniWeb, Red Sentry, Software Secured, Sprocket Security, Stingrai and Strobes state that a retest after remediation is included in some form. The terms differ: CYBRI lists remediation testing on its larger packages, Bugcrowd states 12 months of retesting with one report update, and ImmuniWeb's on-demand product limits retesting to a window after the report. Get the retest terms in writing before you sign.

PTaaS or a traditional penetration test?

A traditional test is a project with a fixed window and a report at the end. PTaaS is better when you ship often, need evidence across a SOC 2 Type II period, or want findings in your ticketing tool as they land. A traditional engagement is better when a contract names a specific firm, method or signed report. Many teams run both: one scoped engagement a year and a platform in between.

Does PTaaS satisfy SOC 2, PCI DSS or ISO 27001?

The platform does not decide that; your auditor or QSA does. PCI DSS v4.0 requirement 11.4 asks for a qualified internal resource or qualified external third party with organizational independence, at least once every 12 months and after significant change. It does not say how the test is delivered. Check with your assessor before you rely on any report, ours included.

Next step

See your own attack surface first.

The free scan checks your public surface without an account and returns a report you can take to any platform above, including the ones that are not us.

Run the free scan

Read next