Editorial standards
The principles behind everything we publish. If we can’t meet them, we don’t publish.
Accuracy over volume
We would rather list fifty firms we have verified than five hundred we haven’t. Every company, accreditation, and claim is checked against a source we can point to. We never fabricate a firm, a review, a rating, a testimonial, or a credential.
Independence
We are not a penetration testing firm, and we are not an accreditation body. We do not sell testing, we confer no credentials, and we are not affiliated with CREST, the NCSC, OWASP, the PCI SSC, or ISO. Our value depends entirely on being independent of the firms we list, so we protect that independence above any single commercial opportunity.
Everything is sourced
Load-bearing claims carry a source. Firm listings link the public record they came from. Where we cite a standard — OWASP, PCI DSS, NCSC guidance — we point to the primary document, not a paraphrase.
No single named author, by design
Our guides are written and maintained by the PenTesting.org editorial team against this standard. We earn trust through verifiable sourcing and a published methodology, not through a personal byline.
Commercial relationships are disclosed and separated
Featured placements are always labelled and never affect editorial order or the accuracy of the data. Referral or affiliate arrangements never change what we recommend or how firms are ranked. Read the full mechanics in our methodology.
Corrections and freshness
We date each listing with when it was last verified and correct errors promptly when they are found or reported. Firms can request corrections to their own listing.