Short answer: PTaaS books human pentesters through a platform, usually for a quarterly or annual test that starts 1 to 3 business days after you book (Cobalt, checked 2026-09-26). Continuous AI pentesting reruns agentic tests of your web apps and APIs as often as daily, and tracks each finding across runs. Many teams run both.
Say you ship twice a week and your last pentest was in March. The PTaaS vendor offers to book testers for the next quarter. An AI pentesting vendor offers to test the app every night. They're selling different things, and the names don't make that obvious.
What is PTaaS?
Penetration testing as a service (PTaaS) is a human pentest bought and run through a software platform. You scope the test in a portal, the vendor assigns testers, findings show up in the portal as testers log them, and you retest fixes from the same place. It usually comes on an annual subscription or a bundle of credits.
The testing is still done by people. What the platform replaces is the email thread, the PDF-only report and the weeks of procurement around a classic consultancy test. Here's how four well-known vendors describe their offer on their own sites.
| Vendor | Who tests | Time to start | How it's priced | Retesting |
|---|---|---|---|---|
| Cobalt | The Cobalt Core community of vetted pentesters, matched to your stack | 1 to 3 business days, depending on tier | Annual packages of credits. One credit equals 8 traditional pentesting hours. Credits don't roll over | Unlimited on-demand retesting for the contract term, on every tier |
| Synack | The Synack Red Team, described as over 1,500 researchers, plus an AI agent called Sara | "Days, not weeks or months", with self-service scoping | Not published. Tests run from 14 days up to 365-day continuous coverage | "Patch Verified" remediation checks |
| HackerOne Pentest | A vetted pool of pentesters matched to the asset and tech stack | Not stated. HackerOne says it typically replies to enquiries within 1 business day | Not published | Testers revisit findings to confirm the fixes |
| BreachLock | In-house certified pentesters (CREST, OSCP and others), with AI handling recon and scanning | 24 to 48 hours to launch | Custom, based on scope, size and frequency | 1 or 2 free manual retests, depending on package (custom on the largest) |
All four were checked on the vendors' own pages on 2026-09-26. Several of them now add AI to the human work: Cobalt sells an autonomous pentest, Synack has Sara, and BreachLock's AI does the recon. The line between the two categories is blurring. What still separates them is who does the testing and how often it happens.
Where is PTaaS strong?
Human judgement is the big one. A good tester notices that the refund endpoint accepts a negative quantity, or that an invited user can approve their own invitation. Those are business-logic flaws, and they depend on understanding what the app is for. The first peer-reviewed live comparison of AI agents and professional testers found that AI agents raised more false positives than every human tester and struggled with GUI-based tasks (we cover that study in AI vs manual pentesting).
PTaaS also covers more ground than web apps. Depending on the vendor, that includes internal and external networks, cloud configuration, mobile apps and LLM features.
And it produces paperwork an auditor or an enterprise customer recognises: a formally scoped engagement by certified testers, with a letter of attestation at the end. Cobalt calls these "audit-quality letters of attestation". If a customer's security questionnaire asks for a third-party pentest by qualified testers, that's the document they mean.
Where is PTaaS limited?
Mostly on frequency and cost per test.
Every test is booked tester time. Even at 1 to 3 business days to start, each test is an engagement with its own scope and test window. Teams rarely book that every week, so in practice PTaaS runs quarterly or annually, with retests of specific fixes in between.
Pricing follows tester hours. Credits, packages or custom quotes all come back to how many human hours you buy. That's fair for skilled work, and it's also why a monthly full retest of the whole app is expensive. Rough market figures for a single human-led web app test are on our pentest cost page, and year-round program prices are in continuous pentesting cost.
Retests cover the fixes, not the app. A retest checks that the findings you fixed stay fixed. It doesn't test the three new endpoints you shipped since, and nobody is watching for an old bug that a merge brought back in a part of the app the retest didn't touch.
Terms vary too. Retest windows of 6 or 12 months, credits that expire at year end and minimum packages are common. Read them before you compare prices.
What is continuous AI pentesting?
AI agents run a full pentest of your web app or API, and the test is saved and rerun on a schedule. Each run is compared with the last, so you see which findings are new, which are still open, which are resolved and which have come back. We explain the model in depth in what is continuous pentesting.
The point isn't to replace a tester for a week. It's to have something test the live app every day, because that's how often it changes and, increasingly, how fast attackers move.
Why test the app surface daily, not quarterly?
Because the time between a flaw going public and someone exploiting it has collapsed, and AI is making the attacker's side faster still.
- Mandiant put the average time to exploit at 5 days in 2023, down from 63 days in 2018 to 2019 (Google Cloud blog, 15 October 2024).
- M-Trends 2026 estimates the mean time to exploit at minus 7 days, meaning exploitation routinely starts before a patch exists. Exploits were the most common way in for the sixth year running, at 32% of intrusions (Mandiant, 23 March 2026).
- VulnCheck found that 28.96% of known exploited vulnerabilities in 2025 were exploited on or before the day their CVE was published, up from 23.6% in 2024 (VulnCheck, 21 January 2026).
- Google's Threat Intelligence Group reported the first zero-day exploit it believes was developed with AI: a 2FA bypass in a web-based admin tool, rooted in a logic flaw, which a criminal group planned to use for mass exploitation. GTIG notes that frontier models are good at spotting exactly this kind of high-level logic error (GTIG, 11 May 2026).
A caveat, to be fair about it. Those numbers measure published CVEs in third-party software. A bug in your own code has no CVE and no disclosure date. But the same AI tooling that shortens exploit development also makes it cheaper to probe custom web apps for logic flaws, and your app changes with every release. If a release on Tuesday opens an IDOR, a quarterly test finds it in weeks. A daily run finds it on Wednesday.
That's why we recommend testing the app surface daily, and treating the annual pentest your auditor asks for as the minimum, not the plan.
PTaaS vs continuous AI pentesting: how do they compare?
This table compares the typical version of each. Individual vendors differ, and some PTaaS vendors now sell continuous programs of their own.
| PTaaS | Continuous AI pentesting (Barrion) | |
|---|---|---|
| Cadence | Per engagement, usually quarterly or annual. Some vendors offer year-round programs | Daily, weekly, monthly, quarterly, every six months, yearly or a custom rhythm, and optionally only when the app has changed |
| Time to first finding | Days: 1 to 3 business days to start (Cobalt) or 24 to 48 hours (BreachLock), then the test window | Hours: a run starts once you approve the scope and finishes within hours. Standard and up is released within one working day after expert review |
| Proof per finding | Findings are confirmed by the tester who logged them | Findings are checked against the live app before they're reported. Confirmed ones come with the request and response. Ones that couldn't be confirmed are kept as lower-confidence leads |
| Regression tracking | Retests of fixed findings within the retest window | Every run labels findings new, still open, resolved or regressed |
| Scope | Broad: web, API, network, cloud, mobile, depending on vendor | Web apps and APIs only |
| Human involvement | People do the testing, with AI assisting at some vendors | AI agents test. A security engineer reviews each report from Standard level up. Light runs have no expert review |
| Pricing model | Tester hours sold as credits, packages or custom quotes, usually annual | Per-run credits with public prices, plans from €199/month. Continuous programs are scoped with sales |
| Start | Sales call, scoping, then booking | Self-serve: set up and start a first run yourself |
| Best fit | Business logic, broad scopes, formal attestation for audits and customers | Teams that ship weekly or faster and want testing on a schedule |
Which one should you choose?
Start with how often your app changes and what your auditors or customers ask for. If you're unsure about cadence, how often to pentest walks through it.
Choose continuous AI pentesting as your main layer if you deploy weekly or faster, your exposure is mostly web apps and APIs, and you want a fixed bug that comes back to show up within a day. It's also the cheaper way to go from "tested once a year" to "tested every day".
Choose PTaaS if you need internal network, cloud, mobile or Active Directory testing, a letter of attestation from named testers, or deep manual work on a complex business flow such as payments, trading or multi-tenant permissions.
Choose both if you're in the most common position: an app that ships often, plus a customer, auditor or framework that expects a human-led test every year. PCI DSS, for example, asks for penetration testing at least every 12 months and after significant changes.
The hybrid most teams end up with
Run continuous AI pentesting on the app surface every day. A typical setup is a daily Light run that fires only when the app has changed, plus a monthly or quarterly Deep run that always fires.
Then book a human-led test once or twice a year for the judgement-heavy paths and for scopes the AI layer doesn't cover. Give the testers your continuous findings history first. They shouldn't spend paid hours rediscovering a reflected XSS or an open redirect the agents already confirmed. That time is better spent on the refund logic.
Done this way, the human test gets sharper and cheaper, and the months between tests are no longer blind.
How Barrion does it
Barrion's AI agents test web apps and APIs the way an attacker would, across 8 testing areas and all 97 OWASP WSTG v4.2 cases. There are five depths, from Light (400 credits, 3 agents, up to €200 per run) to Maximum (20,000 credits, 100 agents, up to €10,000 per run).
Any pentest can be saved and put on a schedule: daily, weekly, monthly, quarterly, every six months, yearly, or a custom rhythm. Each schedule has its own scope and depth, and you choose whether it runs every time or only when your app has changed. You can also trigger runs from your CI/CD pipeline via the Barrion API.
Every run labels its findings new, still open, resolved or regressed. Findings are checked against the live app before they're reported, and ones that can't be confirmed are kept as lower-confidence leads rather than counted as vulnerabilities. From Standard level up, a security engineer reviews each report before release.
You can start a single pentest self-serve. Scheduled pentests come with the Business plan, which is set up through sales. Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup.
What we don't test: internal networks, Active Directory, mobile apps, physical security, social engineering, or threat-led testing (TLPT) under DORA. For those, a PTaaS vendor or a consultancy is the right call, and we'll say so.
Sources
All sources checked 2026-09-26.
Cobalt, Pentesting and Cobalt pricing (credits, start times, retest windows, attestation letters)
Synack, Penetration testing (Synack Red Team, Sara, 14-day to 365-day tests)
HackerOne Pentest (vetted pentesters, retesting, compliance reports)
BreachLock PTaaS (in-house testers, 24 to 48 hour launch) and BreachLock pricing (retest terms), checked 2026-09-26
Mandiant, How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends, Google Cloud blog, 15 October 2024
Mandiant, M-Trends 2026, Google Cloud blog, 23 March 2026
VulnCheck, State of Exploitation 2026, 21 January 2026
Google Threat Intelligence Group, Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access, 11 May 2026
PCI DSS v4.0.1, PCI Security Standards Council, Requirement 11.4
Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing, arXiv 2512.09882, ICLR 2026
Barrion product facts, facts page