Appsecco
Appsecco is a boutique application and product security testing firm delivering manual penetration testing of apps, APIs, cloud/Kubernetes, and AI/MCP systems for global SaaS, fintech, and healthtech customers.
- Company typePrivate
- Founded2015
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Appsecco does
Appsecco is a privately-held application and product security testing firm operating across the United Kingdom and India. The company delivers manual penetration testing engagements for SaaS, fintech, and healthtech customers, with a stated track record of 10+ years in product security, 700+ engagements, and 5,000+ vulnerabilities identified across 150+ organizations. Its service menu spans applications and APIs (web, mobile, REST, GraphQL), cloud and Kubernetes infrastructure with IAM, and AI/MCP attack surfaces (MCP servers, LLM and RAG applications, AI agents and tool use).
Underlying the service is a manual testing methodology that does not rely on automated scanners and instead models real attacker behavior to surface business logic flaws, chained authorization bypasses, and AI/MCP-specific attack paths. The company supports this methodology with an unusually strong public open-source footprint, including an AWS/Azure security training repository (949+ GitHub stars), a Damn Vulnerable Node App lab (756+ stars), a Vulnerable MCP Servers Lab (157+ stars), and an MCP Pentesting Checklist and Universal MCP Client. It also publishes a technical blog, buyer guides, an MCP Buyer Checklist, an RFP template, sample reports, and a security glossary used as a content-driven inbound channel.
The business model is professional services with a recurring tail. Project-based fixed-scope engagements start at $3,500 for core product assessments, with custom pricing for connected infrastructure and AI/MCP scopes; rolling retainer engagements and focused 3-5 day checks supplement the project flow. Each engagement includes a fixed quote before work begins, a report reading call, and a revalidation window. Go-to-market is sales-led with inside-sales handling inbound, supported by content marketing and open-source community channels. Named enterprise customers include Chargebee, Rippling, Agoda, Xendit and Poshmark, and the company supports SOC 2, ISO 27001, PCI DSS, HIPAA, and GDPR-related testing requirements.
Appsecco firmographics
Firmographics- Name
- Appsecco
- Legal name
- Appsecco
- Website
- https://appsecco.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Appsecco is a boutique application and product security testing firm delivering manual penetration testing of apps, APIs, cloud/Kubernetes, and AI/MCP systems for global SaaS, fintech, and healthtech customers.
- Ownership category
- akta.pro rank
Appsecco industry classification
Industry- Product category
- Cybersecurity Services / Penetration Testing
- NAICS
- Testing Laboratories and Services (54138)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- API Security (Discovery, Testing, Runtime Protection) (HDADACAB)
- akta.pro secondary industry
- App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where Appsecco is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Appsecco business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Project-based Security Assessments: Fixed-scope engagements for defined releases, launches, or annual requirements. Pricing starts at $3,500 for core product assessments covering web apps, APIs, authentication, authorization, and business flows. Custom pricing for connected infrastructure and AI/MCP layer testing. Includes standard security report, fix guidance, report reading call, and one revalidation window.
- Rolling Retainer Engagements: Monthly cadence engagements for continuous delivery teams with growing product surfaces. Provides ongoing security visibility with monthly scope plans, status updates, and retest verification on fixes.
- Focused Security Checks: Short, targeted reviews of specific features, integrations, or risk areas lasting 3-5 business days. Ideal for new integrations, sensitive flows (auth, payments), or quick validation before launch.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Pay-as-you-go | Core Product Assessment |
| One time/ perpetual license | Pay-as-you-go | Connected Infrastructure Assessment |
| One time/ perpetual license | Pay-as-you-go | AI / MCP Layer Assessment |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels5 records
Appsecco product offering
Product offeringCore offering
Appsecco provides manual product security testing services covering applications (web, mobile), APIs (REST, GraphQL), cloud infrastructure, Kubernetes, IAM, and emerging AI/MCP attack surfaces. Engagements are delivered as fixed-scope assessments or rolling monthly retainers, and include a standard security report, remediation guidance, a report reading call, and one revalidation window. Core assessments start at $3,500, with custom pricing for connected infrastructure and AI/MCP layer testing.
Product overview
Appsecco offers a unified product security testing platform focused on testing apps, APIs, cloud infrastructure, and AI/MCP systems. The core offering comprises Product Security Testing (covering Apps & APIs, Cloud/K8s/IAM, and Reports), augmented by AI-enabled surface testing (MCP Servers, AI Chatbots & LLM Apps, AI Agents & Tool Use). The portfolio is complemented by open-source tools including the MCP Pentesting Checklist, Universal MCP Client, Vulnerable MCP Servers Lab, DVNA vulnerable app, and AWS/Azure security training materials. Pricing starts at $3,500 for core product assessments, with custom pricing for connected infrastructure and AI/MCP layer testing. Fixed quotes, report reading calls, and one revalidation window are included in every engagement.
Differentiator
Problem solved
Functional benefit
Products and services
- Product Security Testing
Quantifiable outcome
- 5,000+ vulnerabilities discovered across 700+ engagements
- +2 more outcomes
Companies that use Appsecco
Customer profileNamed customers9 records
Segments5 records
Ideal customer profiles5 records
Appsecco technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability6 records
Feature3 records
Appsecco partnerships and signals
Strategic signalScale indicators7 records
Recent moves5 records
Expansion highlights5 records
Appsecco competitors and assessment
Company assessmentBroad incumbents
- NCC Group: Large UK-listed cybersecurity consultancy delivering application, network, and cloud penetration testing globally. Closest broad incumbent to Appsecco given UK overlap and full pentest portfolio, but Appsecco is more specialized in manual product security and AI/MCP testing.
- NetSPI: US-based penetration testing and attack surface management firm with a broad portfolio including application, cloud, and AI security testing. Larger scale than Appsecco but overlapping in core app/API/cloud pentest offerings to enterprise SaaS and fintech buyers.
- HackerOne: Bug bounty and crowdsourced security testing platform serving many of the same enterprise SaaS and fintech buyers. Indirect peer — overlaps on finding production vulnerabilities but uses crowdsourced testers rather than Appsecco's curated manual methodology.
- WithSecure (formerly F-Secure Consulting): European-headquartered cybersecurity vendor with a dedicated offensive security consulting arm covering applications, cloud, and emerging technology testing. Broader portfolio than Appsecco but overlapping on enterprise app/cloud pentest engagements across EMEA.
Direct peers
- Bishop Fox: US boutique offensive security firm focused on red teaming, application, and cloud pentesting with a research-driven brand. Directly comparable to Appsecco in methodology emphasis on manual testing and public research, though Appsecco's MCP/AI specialization is differentiated.
- Trail of Bits: Research-led security consultancy publishing open-source tools (Slither, Echidna) and conducting smart contract plus application security audits. Highly comparable to Appsecco's open-source content moat and boutique testing focus, with adjacent expertise in protocols rather than AI/MCP.
- Cure53: German boutique penetration testing firm with strong reputation in web application and browser security research. Similar size and model to Appsecco with comparable manual methodology emphasis, though Cure53 is more browser-focused and less oriented to AI/MCP surfaces.
- Pen Test Partners: UK-based penetration testing consultancy covering applications, cloud, and infrastructure. Direct geographic and service overlap with Appsecco in the UK and India delivery market, with comparable scope of testing engagements.
- Securitum: Polish security boutique specializing in web application and API penetration testing with research-driven branding. Comparable to Appsecco in boutique-size and methodology emphasis, with similar delivery model targeting European and global SaaS clients.
Emerging players
- Cobalt: Pentest-as-a-service platform connecting customers to vetted freelance testers with standardized scoping and delivery. Competes with Appsecco on standardized web/API pentests where Appsecco's manual-only positioning differs, while Cobalt's platformized approach offers faster procurement for buyers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Appsecco social profiles
Digital presenceAppsecco compliance and trust
Trust signalCompliance5 records
Appsecco financial estimates
Financial estimateRevenue estimate
Valuation estimate
Appsecco leadership team
Management profileNumber of profiles
Profiles2 records
Appsecco funding detail
Funding detailFunding overview
Funding rounds1 record
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Appsecco M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Appsecco
What does Appsecco do?
Appsecco provides manual product security testing services covering applications (web, mobile), APIs (REST, GraphQL), cloud infrastructure, Kubernetes, IAM, and emerging AI/MCP attack surfaces. Engagements are delivered as fixed-scope assessments or rolling monthly retainers, and include a standard security report, remediation guidance, a report reading call, and one revalidation window. Core assessments start at $3,500, with custom pricing for connected infrastructure and AI/MCP layer testing.
Is Appsecco a public or private company?
Appsecco is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Appsecco founded?
Appsecco was founded in 2015. It employs 11 to 50 people.
Where is Appsecco based?
Appsecco is headquartered in London, United Kingdom, in the Europe region.
How does Appsecco make money?
Three revenue lines are on record. Project-based Security Assessments are the primary driver. The others are rolling Retainer Engagements and focused Security Checks.
Who are Appsecco's main competitors?
Broad incumbents on record are NCC Group, NetSPI, HackerOne and WithSecure (formerly F-Secure Consulting). Direct peers are Bishop Fox, Trail of Bits, Cure53, Pen Test Partners and Securitum. Cobalt is listed as an emerging player.
Does Appsecco have an API?
No public API is recorded for Appsecco.
What industry is Appsecco in?
Appsecco's product category is Cybersecurity Services / Penetration Testing. Its primary akta.pro industry code is HDADACAB, API Security (Discovery, Testing, Runtime Protection), with a secondary code of BPAMADAJ, App Security, Compliance & Review Automation Platforms. Its NAICS code is 54138 and its SIC code is 8734.