# Bishop Fox privacy rating

US offensive security firm based in Tempe, Arizona, that provides penetration testing, red teaming and continuous attack surface testing, and develops open-source tools such as Sliver.

## Summary

Bishop Fox scores 14 out of 100 (grade F) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It does not meet publishes full reports, audits open-source projects and no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.

- Website: https://bishopfox.com
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Home page trackers: Google Tag Manager
- Category: [Security audit firms](https://privacyratings.com/security-audit-firms/)
- Grade: F (14/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Publishes full reports | No | The firm does not publish client audit reports. |  |
| Audits open-source projects | No | No public audits of open-source projects are published. |  |
| Public research | Yes | Publishes regular research, advisories and open-source offensive security tools. | https://bishopfox.com/tools |
| No trackers on website | No | The home page loads Google Tag Manager. |  |

Source: https://privacyratings.com/security-audit-firms/bishop-fox/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/security-audit-firms/bishop-fox.md
