# IOActive privacy rating

US security services firm based in Seattle that performs penetration testing, hardware and embedded security assessments and research, with a focus on industrial, transport and IoT systems.

## Summary

IOActive scores 14 out of 100 (grade F) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It does not meet publishes full reports, audits open-source projects and no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.

- Website: https://www.ioactive.com
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Home page trackers: Cookiebot (not scored), Google Analytics, Google Fonts (not scored), Google Tag Manager, LinkedIn Insight
- Category: [Security audit firms](https://privacyratings.com/security-audit-firms/)
- Grade: F (14/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Publishes full reports | No | The firm does not publish client audit reports. |  |
| Audits open-source projects | No | No public audits of open-source projects are published. |  |
| Public research | Yes | Publishes regular research papers, vulnerability disclosures and tools. | https://www.ioactive.com/resources/research/ |
| No trackers on website | No | The home page loads Google Analytics, Google Tag Manager and LinkedIn Insight. |  |

Source: https://privacyratings.com/security-audit-firms/ioactive/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/security-audit-firms/ioactive.md
