Every provider on this ranking is scored against the same five weighted criteria, using only evidence we can verify independently. This page documents the full process, so you can judge the ranking the way you'd judge any of the vendors on it.
Scores are weighted averages across five categories. Technical depth and industry coverage carry the most weight because they correlate most directly with whether a test actually finds something a real attacker would use. Where possible, we benchmark disclosed methodology against public frameworks such as the OWASP Web Security Testing Guide and the NIST SP 800-115 technical testing guide.
Public CVEs, original research, disclosed methodology
Verified experience across finance, industrial, crypto, e-commerce
CREST, OSCP/OSCE-holding teams, ISO 27001, QSA/FedRAMP where relevant
Disclosure policy, public case studies, bug bounty track record
CVSS scoring, proof-of-concept detail, remediation retest process