Security audit firms
Trail of Bits privacy rating
US security research and engineering firm that audits software, cryptography, blockchain and AI systems, and develops open-source security tools such as Slither and Echidna.
Summary
Trail of Bits scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and public research. It does not meet no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.
Score 86 out of 100. How scoring works
Criteria
-
Yes
Publishes full reports Weight 3 of 3
Are full audit reports routinely published, with client consent, rather than only summaries or badges?
The public publications repository lists hundreds of full security review reports.
-
Yes
Audits open-source projects Weight 2 of 3
Does the firm regularly audit open-source software and non-profit projects?
Public reviews include many open-source projects, such as PyPI Warehouse, the Linux kernel release signing process and OSTIF-funded audits like NATS.
-
Yes
Public research Weight 1 of 3
Does the firm publish security research, advisories or tools?
Publishes a regular research blog, conference papers and open-source security tools.
-
No
No trackers on website Weight 1 of 3
Is the firm's website free of third-party trackers?
The home page loads HubSpot and Cloudflare Web Analytics.