Fact-checking, corrections and disclosure
The sourcing standard every claim on this site has to clear, how we handle a claim we cannot confirm, and the full position on advertising, affiliates and ownership.
How we fact-check
Every company-specific claim on this site — a certification, a UAE office, a service scope, a founding year — is checked against the company's own official site and, wherever one exists, a primary register:
- DESC's certified-provider register for any Dubai Cyber Force claim.
- The CREST Marketplace and CREST member listings for any CREST claim.
- Independent business press with a named source, or a company-registry record, for firmographic facts such as ownership, founding year or leadership.
A claim that does not clear that bar is not published as fact. It is either left out, or shown with an explicit note saying it is not independently confirmed — which is how two entries on the current ranking are handled.
One detail that matters more than it sounds
We search the vendor's registered legal entity name, not its trading name. Several providers on this list appear on a register under a name a buyer would not recognise from the marketing site. Checking only the brand name produces false negatives, and we have seen published comparisons make exactly that mistake.
Why we sometimes publish an unconfirmed claim, flagged
When a vendor advertises an accreditation we cannot find on the certifying body's register, we say so rather than staying silent. A labelled gap — "this is claimed on the vendor's site and is not on the register we checked, on this date" — is more useful to a buyer than an omission, which they would read as an absence of information rather than an absence of evidence.
We use this sparingly, we name what we checked and when, and we do not editorialise about motive. A missing register entry can mean a lapsed certification, an accreditation held by individuals rather than the company, or a claim that was never accurate. A register cannot tell the three apart, so neither do we.
No fabricated trust signals
This site publishes no star ratings, no aggregate review scores, no testimonials, and no Review or AggregateRating structured data for any listed company. It publishes no invented author personas and no stock-photo headshots. If we ever publish client feedback it will be attributable, dated, and clearly separated from editorial judgement.
We also do not publish price figures we cannot source. Penetration testing costs vary enough by scope that a plausible-looking number with no source behind it would be a guess wearing the costume of research.
Superlatives
The page title uses the phrase buyers search for. The content does not claim any single company is "the best", "leading" or "largest" unless the specific claim is supportable and stated narrowly — for example, "the largest UAE-headquartered provider on this list", which is checkable, rather than "the region's leading firm", which is not.
Corrections
Anyone, including a listed company, can request a correction:
- For a listing change, addition or removal, use Submit a company, which sets out the evidence we need.
- For anything else — a factual error, a broken link, a source we should have used — use the address on the contact page.
Submitted evidence is assessed against the same primary-source standard described above. That applies to evidence sent by a company about itself: a vendor's own assertion does not become verified by arriving directly from the vendor. Material corrections — a changed certification status, a wrong founding year or ownership, a company added or removed — are logged with a visible updated date on the affected page.
Advertising and affiliate disclosure
This site currently carries no paid placements, no sponsored listings and no affiliate links. Links to company websites are ordinary editorial links.
If that changes, a sponsored listing will be labelled "Sponsored" in the listing itself, linked with rel="sponsored", and disclosed both on this page and on the affected company's card. A paid placement will never be presented as an independent research finding, and paid status will never affect the position of any other company.
Ownership and conflicts
The publisher has no ownership, commercial or client relationship with any company on this ranking. If that changes for any company at any position, the relationship will be disclosed on this page, on the methodology page, and on that company's card, with a statement of how it bears on the position.
One disclosure applies today: part of Paranoid Security's service and positioning detail was supplied by the company for this review rather than gathered from third parties. The methodology page records it, and it is the reason that entry is ranked last on our independent-evidence criterion.
We also treat vendor-published comparison content as a conflict when we meet it in research. Where a source is a company writing about itself or its competitors, it is a lead to verify, never evidence for a position.
Independence of judgement
Nothing on this site is a hands-on technical audit of any vendor's testing quality. It is a comparison of publicly documented capability, accreditation and positioning. Treat it as one input to a vendor selection process alongside reference checks, a sample report and a scoped RFP — not as a substitute for them.
Scope limits
This site covers UAE external penetration testing. We do not rank managed SOC or MSSP providers, antivirus, EDR or WAF vendors, ISO 27001 certification bodies, free scanning tools, security training providers, or software procurement platforms, even when a company profiled here also sells those services.
Not advice
This site does not provide legal, regulatory, procurement or investment advice. Statements about UAE regulatory frameworks are background drawn from primary sources and linked so you can read them yourself. Whether any framework applies to your organisation is a question for your compliance team or counsel.