Security audit firms
Radically Open Security privacy rating
Dutch not-for-profit security firm that performs penetration tests and code audits, including for open-source and public-interest projects, and sends most of its profits to the NLnet Foundation.
Summary
Radically Open Security scores 93 out of 100 (grade A) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and no trackers on website. It partly meets public research. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.
Score 93 out of 100. How scoring works
Criteria
-
Yes
Publishes full reports Weight 3 of 3
Are full audit reports routinely published, with client consent, rather than only summaries or badges?
The portfolio links a collection of full public reports hosted on GitHub.
-
Yes
Audits open-source projects Weight 2 of 3
Does the firm regularly audit open-source software and non-profit projects?
Public reports include audits of GlobaLeaks, Ushahidi, F-Droid, Tauri and other open-source projects, some funded by the Open Technology Fund.
-
Partial
Public research Weight 1 of 3
Does the firm publish security research, advisories or tools?
Publishes open-source tooling such as the PenText report system and gives occasional talks.
-
Yes
No trackers on website Weight 1 of 3
Is the firm's website free of third-party trackers?
The privacy policy states the website uses no cookies and does not track or analyze visitors, and the tracker test found none.