Security audit firms compared
Independent firms that audit software and services for security and privacy. The ratings focus on whether their reports are public.
16 security audit firms are rated against 4 public criteria, and 16 have enough evidence for a letter grade. Our pick is Cure53. Of the 16 with a known jurisdiction, 6 are based in a Five Eyes country, and 12 in the wider Fourteen Eyes.
Criteria for this category · Suggest an addition · Markdown
| Name | Grade | Score | Data | Jurisdiction | Publishes full reports | Audits open-source projects | Public research | No trackers on website |
|---|---|---|---|---|---|---|---|---|
Cure53 Our pick Berlin security firm that performs penetration tests and source code audits of web, mobile, browser, VPN and cryptographic software, and publishes many client reports. |
Grade A | 100 | 100% | Germany Fourteen Eyes | Yes | Yes | Yes | Yes |
German security firm in Aachen that performs source code audits, penetration tests, fuzzing and red teaming, with many published audits of open-source projects. |
Grade A | 100 | 100% | Germany Fourteen Eyes | Yes | Yes | Yes | Yes |
Swedish security consultancy in Gothenburg that performs penetration tests, code reviews and infrastructure audits, including published audits of Mullvad VPN and OTF-funded projects. |
Grade A | 93 | 100% | Sweden Fourteen Eyes | Yes | Yes | Partial | Yes |
Berlin security consultancy that audits cryptographic protocols, blockchain systems, wallets and privacy software, and develops open-source privacy tools. |
Grade A | 93 | 100% | Germany Fourteen Eyes | Yes | Yes | Partial | Yes |
Dutch not-for-profit security firm that performs penetration tests and code audits, including for open-source and public-interest projects, and sends most of its profits to the NLnet Foundation. |
Grade A | 93 | 100% | Netherlands Nine Eyes | Yes | Yes | Partial | Yes |
Security firm specialising in mobile, web and cloud penetration tests and code audits, with many published audits of open-source and digital-rights projects funded by OSTIF and the Open Technology Fund. |
Grade B | 86 | 100% | Ireland Outside Eyes | Yes | Yes | Yes | No |
Application security firm with offices in San Francisco and San Marino that tests web, mobile, desktop, cloud and Electron applications and spends part of its time on public security research. |
Grade B | 86 | 100% | United States Five Eyes | Yes | Partial | Yes | Yes |
UK cyber security company that provides penetration testing, cryptography reviews, incident response and managed security services. |
Grade B | 86 | 100% | United Kingdom Five Eyes | Yes | Yes | Yes | No |
French security research company that performs audits, reverse engineering and vulnerability research, and develops open-source tools such as LIEF and Triton. |
Grade B | 86 | 100% | France Nine Eyes | Yes | Yes | Yes | No |
Polish penetration testing company in Kraków that tests web, mobile and infrastructure systems and runs the Sekurak security publication and training. |
Grade B | 86 | 100% | Poland Outside Eyes | Yes | Partial | Yes | Yes |
US security research and engineering firm that audits software, cryptography, blockchain and AI systems, and develops open-source security tools such as Slither and Echidna. |
Grade B | 86 | 100% | United States Five Eyes | Yes | Yes | Yes | No |
Cybersecurity division of the Swiss Kudelski Group that provides managed detection and response, incident response, advisory services and security assessments. |
Grade D | 50 | 100% | Switzerland Outside Eyes | Partial | Partial | Yes | No |
US offensive security firm based in Tempe, Arizona, that provides penetration testing, red teaming and continuous attack surface testing, and develops open-source tools such as Sliver. |
Grade F | 14 | 100% | United States Five Eyes | No | No | Yes | No |
US application security consultancy based in Brooklyn, New York, that performs penetration tests and source code reviews of web, mobile, cloud and embedded software. |
Grade F | 14 | 100% | United States Five Eyes | No | No | Yes | No |
US security services firm based in Seattle that performs penetration testing, hardware and embedded security assessments and research, with a focus on industrial, transport and IoT systems. |
Grade F | 14 | 100% | United States Five Eyes | No | No | Yes | No |
Austrian cyber security consultancy, part of Atos, that provides penetration testing, red teaming, incident response and security consulting, and runs a vulnerability research lab. |
Grade F | 14 | 100% | Austria Outside Eyes | No | No | Yes | No |
Questions
What is the most private option among security audit firms?
Our pick is Cure53. Publishes a large public library of full audit reports, many for open-source and privacy projects, and maintains the DOMPurify sanitizer. Its website uses no cookies or analytics.
How are security audit firms rated?
Each entry answers 4 questions: publishes full reports, audits open-source projects, public research and no trackers on website. Answers need links to evidence. See the full criteria.
Does jurisdiction matter?
Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.
Comparisons
- Cure53 vs X41 D-Sec
- Cure53 vs Assured
- Cure53 vs Least Authority
- Cure53 vs Radically Open Security
- Cure53 vs 7ASecurity
- Cure53 vs Doyensec
- Cure53 vs NCC Group
- Cure53 vs Quarkslab
- Cure53 vs Securitum
- Cure53 vs Trail of Bits
- Cure53 vs Kudelski Security
- Cure53 vs Bishop Fox
- Cure53 vs Include Security
- Cure53 vs IOActive
- Cure53 vs SEC Consult