AppSec Audit Review

Who writes this

Dana Sarraf, Security Research Editor

Dana Sarraf compiles and maintains this ranking of web application security audit firms serving the UAE. She does not work for, consult for, or hold any interest in a company that appears in it.

Editor since 2026 · contactable at hello@best-web-application-security-audit-companies.com

Evidence in, register checked, score out

The remit

The Security Research Editor role exists to keep this research independent of any one firm's commercial interests. In practice that means four standing responsibilities:

  • Reviewing each firm's publicly available service pages, accreditation claims and published research
  • Applying the eight-point scoring framework consistently across every entry, including the entry ranked first
  • Checking accreditation claims against the accrediting body's public register wherever one exists, starting with the CREST register
  • Updating the ranking as firms' offerings, accreditations or market position change

Background

Dana Sarraf's work on this site is research and comparison, not penetration testing. The analysis draws on published industry standards and frameworks — the OWASP Web Security Testing Guide, PCI DSS, and the regional frameworks that govern UAE buyers, including DESC's requirements and the UAE Personal Data Protection Law — rather than on firsthand offensive security engagements.

That boundary is stated deliberately. A comparison page that implies its author has tested the firms it ranks is claiming access nobody publishing a public listicle has. What this role can do is read what each firm publishes, check the checkable parts against primary sources, and apply one framework to all ten without exception. What it cannot do is tell you how a given firm performs on your application, which is why the ranking ends in fifteen questions to ask rather than a verdict.

What a review actually involves

A review is not a re-read of the page. Each cycle works through the same sequence for all ten firms, in the same order, so that a change in one entry's position can always be traced to a change in evidence rather than a change of mind.

  1. Re-fetch every firm's service pages and confirm the named service still exists and still describes manual testing.
  2. Re-check each accreditation against the accrediting body's register, and record which of the three states applies: the company is registered, only individual staff hold certifications, or neither is listed.
  3. Re-verify all ten outbound links resolve to the firm's own official domain, since vendors reorganize their sites more often than they announce it.
  4. Search for new public evidence — research, CVE credits, case studies, independent coverage — that would move a firm's public track record score.
  5. Re-apply the framework, adjust positions where the evidence moved, and stamp the review date on the ranking page.

Where a change is made, the previous claim is not quietly overwritten with a better-sounding one: an entry that used to say a firm held an accreditation and now says it is not listed reflects the register, and that is the whole point of checking it.

Independence

Employment
No current or past employment with any firm in this ranking.
Commercial interest
No consulting arrangement, referral fee, equity holding or advisory position in any ranked firm.
Pre-publication review
No firm sees, reviews or approves its entry before publication, and no firm is told its position in advance.
Editorial control
Ranking order is not discussed with the firms before publication and is not renegotiated with them afterwards. Factual corrections are a separate process, set out in the editorial policy.

Get in touch

Spotted something inaccurate, or think a firm deserves inclusion? Corrections that come with a public source get handled fastest.

Two ways in

Submissions go through the inclusion criteria; everything else goes to the editorial inbox.

Submit a company Contact the editor