# Security audit firms privacy ratings

Independent firms that audit software and services for security and privacy. The ratings focus on whether their reports are public.

**Our pick:** [Cure53](https://privacyratings.com/security-audit-firms/cure53/): Publishes a large public library of full audit reports, many for open-source and privacy projects, and maintains the DOMPurify sanitizer. Its website uses no cookies or analytics.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Cure53](https://privacyratings.com/security-audit-firms/cure53/) (our pick) | A (100/100) | Germany (Fourteen Eyes) | Berlin security firm that performs penetration tests and source code audits of web, mobile, browser, VPN and cryptographic software, and publishes many client reports. |
| [X41 D-Sec](https://privacyratings.com/security-audit-firms/x41-d-sec/) | A (100/100) | Germany (Fourteen Eyes) | German security firm in Aachen that performs source code audits, penetration tests, fuzzing and red teaming, with many published audits of open-source projects. |
| [Assured](https://privacyratings.com/security-audit-firms/assured/) | A (93/100) | Sweden (Fourteen Eyes) | Swedish security consultancy in Gothenburg that performs penetration tests, code reviews and infrastructure audits, including published audits of Mullvad VPN and OTF-funded projects. |
| [Least Authority](https://privacyratings.com/security-audit-firms/least-authority/) | A (93/100) | Germany (Fourteen Eyes) | Berlin security consultancy that audits cryptographic protocols, blockchain systems, wallets and privacy software, and develops open-source privacy tools. |
| [Radically Open Security](https://privacyratings.com/security-audit-firms/radically-open-security/) | A (93/100) | Netherlands (Nine Eyes) | Dutch not-for-profit security firm that performs penetration tests and code audits, including for open-source and public-interest projects, and sends most of its profits to the NLnet Foundation. |
| [7ASecurity](https://privacyratings.com/security-audit-firms/7asecurity/) | B (86/100) | Ireland | Security firm specialising in mobile, web and cloud penetration tests and code audits, with many published audits of open-source and digital-rights projects funded by OSTIF and the Open Technology Fund. |
| [Doyensec](https://privacyratings.com/security-audit-firms/doyensec/) | B (86/100) | United States (Five Eyes) | Application security firm with offices in San Francisco and San Marino that tests web, mobile, desktop, cloud and Electron applications and spends part of its time on public security research. |
| [NCC Group](https://privacyratings.com/security-audit-firms/ncc-group/) | B (86/100) | United Kingdom (Five Eyes) | UK cyber security company that provides penetration testing, cryptography reviews, incident response and managed security services. |
| [Quarkslab](https://privacyratings.com/security-audit-firms/quarkslab/) | B (86/100) | France (Nine Eyes) | French security research company that performs audits, reverse engineering and vulnerability research, and develops open-source tools such as LIEF and Triton. |
| [Securitum](https://privacyratings.com/security-audit-firms/securitum/) | B (86/100) | Poland | Polish penetration testing company in Kraków that tests web, mobile and infrastructure systems and runs the Sekurak security publication and training. |
| [Trail of Bits](https://privacyratings.com/security-audit-firms/trail-of-bits/) | B (86/100) | United States (Five Eyes) | US security research and engineering firm that audits software, cryptography, blockchain and AI systems, and develops open-source security tools such as Slither and Echidna. |
| [Kudelski Security](https://privacyratings.com/security-audit-firms/kudelski-security/) | D (50/100) | Switzerland | Cybersecurity division of the Swiss Kudelski Group that provides managed detection and response, incident response, advisory services and security assessments. |
| [Bishop Fox](https://privacyratings.com/security-audit-firms/bishop-fox/) | F (14/100) | United States (Five Eyes) | US offensive security firm based in Tempe, Arizona, that provides penetration testing, red teaming and continuous attack surface testing, and develops open-source tools such as Sliver. |
| [Include Security](https://privacyratings.com/security-audit-firms/include-security/) | F (14/100) | United States (Five Eyes) | US application security consultancy based in Brooklyn, New York, that performs penetration tests and source code reviews of web, mobile, cloud and embedded software. |
| [IOActive](https://privacyratings.com/security-audit-firms/ioactive/) | F (14/100) | United States (Five Eyes) | US security services firm based in Seattle that performs penetration testing, hardware and embedded security assessments and research, with a focus on industrial, transport and IoT systems. |
| [SEC Consult](https://privacyratings.com/security-audit-firms/sec-consult/) | F (14/100) | Austria | Austrian cyber security consultancy, part of Atos, that provides penetration testing, red teaming, incident response and security consulting, and runs a vulnerability research lab. |

## Criteria

- **Publishes full reports** (weight 3): Are full audit reports routinely published, with client consent, rather than only summaries or badges?
- **Audits open-source projects** (weight 2): Does the firm regularly audit open-source software and non-profit projects?
- **Public research** (weight 1): Does the firm publish security research, advisories or tools?
- **No trackers on website** (weight 1): Is the firm's website free of third-party trackers?

Source: https://privacyratings.com/security-audit-firms/
