# Penetration testing as a service: what AI models recommend, September 2026

IT AI Recommendation Index, September 2026 Edition. Asked as "penetration testing service" and as "pentest-as-a-service provider", six framings each, to twelve models with search on, on behalf of a mid-market B2B company. Page: https://it-ai-index.com/security/penetration-testing-as-a-service/

**Standing:** Cobalt leads with 44% of first choices; verdict clear leader. 45 first choices across the direct, paraphrase, budget and scale prompts.

## First-choice share

| # | Product | Share | Negative rate | Labels |
|---|---|---|---|---|
| 1 | Cobalt | 44% | 5% | 40 |
| 2 | Astra Security | 13% | 0% | 26 |
| 3 | BreachLock | 9% | 3% | 30 |
| 4 | NetSPI | 2% | 9% | 22 |
| 5 | Bishop Fox | 0% | 6% | 16 |
| 6 | Synack | 0% | 11% | 18 |
| 7 | Bugcrowd | 0% | 30% | 10 |
| 8 | HackerOne | 0% | 30% | 10 |

## Each model's first choice on the direct prompt

- Claude Haiku 4.5: no first choice
- GPT-5.4 mini: Cobalt; alternatives Astra Security, HackerOne, Packetlabs, Thoropass Pentesting
- Gemini 3.5 Flash: Cobalt; alternatives BreachLock, Cybri, NetSPI
- Perplexity Sonar: Cobalt; alternatives BreachLock, DeepStrike, Prescient Security, Stingrai
- Grok 4.1 Fast: Packetlabs; alternatives BreachLock, Cobalt
- Mistral Small: Cobalt; alternatives BreachLock, Packetlabs, Stingrai
- DeepSeek V4 Flash: Cobalt; alternatives Astra Security, BreachLock, NetSPI, Packetlabs
- Llama 4 Maverick: Cobalt; alternatives DeepStrike, Echelon Cyber
- Qwen 3.7 Flash: Cobalt; alternatives Coalfire, Kforce, Synack, Trustwave
- Kimi K2: Cobalt; alternatives BreachLock, NetSPI, UnderDefense
- GLM 4.7 FlashX: Cobalt, NetSPI; alternatives Astra Security, Bishop Fox, BreachLock, Secureworks
- MiniMax M2.5: Stingrai; alternatives Cobalt, Invadel

## Sources the answers cite

62 of 72 answers came back with a source list, from 12 of 12 models. Sites named in the most answers:

- deepstrike.io: 37 answers, 64 citations
- synack.com: 30 answers, 39 citations
- underdefense.com: 21 answers, 24 citations
- techrepublic.com: 20 answers, 21 citations
- stingrai.io: 17 answers, 24 citations
- clutch.co: 15 answers, 22 citations
- getastra.com: 15 answers, 21 citations
- softwaresecured.com: 15 answers, 17 citations

Pages named in the most answers:

- https://synack.com/blog/best-penetration-testing-companies (21 answers)
- https://techrepublic.com/article/best-penetration-testing-companies (19 answers)
- https://underdefense.com/blog/penetration-testing-services (19 answers)
- https://clutch.co/it-services/cybersecurity/penetration-testing (15 answers)
- https://deepstrike.io/blog/top-penetration-testing-companies (15 answers)
- https://deepstrike.io/blog/top-penetration-testing-as-a-service-ptaas (12 answers)
- https://terra.security/blog/top-10-penetration-testing-as-a-service-ptaas-providers (12 answers)
- https://soc2auditors.org/penetration-testing-firms (10 answers)
- https://softwaresecured.com/post/top-10-penetration-testing-vendors (10 answers)
- https://artificesecurity.com/penetration-testing-firms-red-flags (8 answers)

## Warned against

- HackerOne: 3 of 10 labels negative. "While good for finding unique bugs, tester continuity is lower because you never know which specific hacker will test your system next." (Qwen 3.7 Flash, comparative prompt)
- Acunetix: 2 of 6 labels negative. "but it is more of a web app security product than a full manual pentest firm" (Perplexity Sonar, budget prompt)
- Bugcrowd: 3 of 10 labels negative. "typically more expensive for enterprise‑scale needs; often better suited to large, complex programs" (GLM 4.7 FlashX, paraphrase prompt)
- Cobalt: 2 of 40 labels negative. "though it is more of a managed marketplace than a low-cost commodity service" (Perplexity Sonar, budget prompt)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
