# Radically Open Security privacy rating

Dutch not-for-profit security firm that performs penetration tests and code audits, including for open-source and public-interest projects, and sends most of its profits to the NLnet Foundation.

## Summary

Radically Open Security scores 93 out of 100 (grade A) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and no trackers on website. It partly meets public research. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.

- Website: https://www.radicallyopensecurity.com
- Jurisdiction: Netherlands. Nine Eyes member. EU member (GDPR).
- Home page trackers: none found
- Category: [Security audit firms](https://privacyratings.com/security-audit-firms/)
- Grade: A (93/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Publishes full reports | Yes | The portfolio links a collection of full public reports hosted on GitHub. | https://www.radicallyopensecurity.com/our-portfolio/ |
| Audits open-source projects | Yes | Public reports include audits of GlobaLeaks, Ushahidi, F-Droid, Tauri and other open-source projects, some funded by the Open Technology Fund. | https://www.radicallyopensecurity.com/our-portfolio/ |
| Public research | Partial | Publishes open-source tooling such as the PenText report system and gives occasional talks. | https://github.com/radicallyopensecurity/pentext |
| No trackers on website | Yes | The privacy policy states the website uses no cookies and does not track or analyze visitors, and the tracker test found none. | https://raw.githubusercontent.com/radicallyopensecurity/ros-website/main/ROS_Privacy_Policy__-_V1.0_-_2022.pdf |

Source: https://privacyratings.com/security-audit-firms/radically-open-security/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/security-audit-firms/radically-open-security.md
