ChaptersCircleEventsBlog
Join us for the in-person CCSK Azure course at Black Hat from August 4–5! Register now for a hands-on deep dive and secure your spot now!

STAR Registry Listing for

Penetration Testing as a Service (PTAAS)

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

Penetration Testing as a Service (PTAAS)

Penetration Testing as a Service (PTAAS)

Cobalt is redefining the modern pentest for companies who want serious hacker-like testing built into their development cycle. Forget about old school, overpriced PDF pen test reports with low quality findings — and never pay for re-testing again.

At Cobalt, we use a combination of data, technology and talent to meet the security challenges of the modern web or mobile application, and ensure we provide the smartest, most efficient services possible. From Cobalt Central, our powerful vulnerability dashboard, to Cobalt Insights, which gives you an intelligent overview of your application security program, we are driven by great technology. Our pentest is built to satisfy requirements you might have as part of your sales process to verify your security posture, including compliance. Your reports are automatically updated when findings. We can also fulfill the requirement for most certifications including vendor assessments, PCI, HIPAA and SOC-2.

Information about Penetration Testing as a Service (PTAAS)
Listed Since: 06/11/2025
Last Updated: 06/11/2025

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.3

CAIQ 4.0.3 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).