AppSec Audit Review

Inclusion requests

Submit a Company for Review

We add firms to this ranking as we identify companies that meet the inclusion criteria. If you run or represent a web application security audit or penetration testing firm and believe it should be reviewed, send the details below.

Reviewed by Dana Sarraf, Security Research Editor · no fee, at any stage

Check the criteria first

A firm is eligible for review if it meets all four of these. Submissions that miss one are not reviewed, so it is worth reading them properly before writing in.

  • It publicly offers web application penetration testing or a web application security audit as a named service
  • It serves UAE-based clients directly, or is prominent enough in the broader market that UAE buyers would evaluate it alongside local specialists
  • It performs manual testing as part of its methodology — automated-scan-only services are not eligible
  • It has a working, publicly accessible website describing those services

The editorial policy sets out how submissions are evaluated once received, and what would keep a firm out.

What to include

Company and site
Legal company name and the official website URL. Not a landing page, an agency profile, or a directory listing.
Relevant service
The primary offering relevant to web application security: penetration testing, audit, or both, with the URL of the service page describing it.
Accreditations
Any credentials held — CREST, DESC, ISO 27001 or equivalent — with a link to the accrediting body's public register entry where one exists. A register link is worth more than a certificate image.
UAE presence
Office location if you have one, or the client base you serve remotely. Either is fine; we record which.
Track record
Published research, CVE credits, case studies or third-party coverage you would like considered under the public track record criterion.

What happens next

A submission does not guarantee inclusion. Submitted firms are reviewed against the same eight-point framework applied to every existing entry, using only publicly verifiable information — which means a submission is a pointer to evidence, not the evidence itself. Anything you tell us that we cannot check from a public source will not appear on the page.

If a firm meets the criteria, it is added at the next scheduled review. If it does not, we will not publish it, and we will not publicly state the reason either; the criteria above are the basis for every decision, and publishing a rejection rationale about a named company is not something a comparison page should be doing.

We do not accept payment for inclusion or for a specific ranking position, and a submission creates no commercial relationship between the submitting firm and this site.

How to submit

Email the details above to the editorial address. There is no form, no account and no portal — a plain email with working links is the fastest route in, and the only one.

Before you write in

If your firm is already in the ranking and you have spotted a factual error, that is a correction rather than a submission — see the correction policy, which is a faster process with a different standard of evidence.