AppSec
AppSec is a Riyadh-based application security services firm founded in 2009 that provides SSDLC, DevSecOps, and security testing consulting across SAST, DAST, SCA, IAST, and penetration testing to government, banking, fintech, telecom, and retail clients in the Middle East via three tiered subscription packages.
- Company typePrivate
- Founded2009
- HeadquartersRiyadh, Saudi Arabia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What AppSec does
AppSec is a Riyadh-based, privately held application security services company founded in 2009 that provides consulting, security testing, and DevSecOps enablement to government, semi-government, banking, fintech, telecommunications, and retail clients across the Middle East, with operational presence in Saudi Arabia and selective activity in the UAE. The company delivers the full secure software development lifecycle (SSDLC), including SSDLC framework design, API security design review, software supply chain security, DevSecOps integration into CI/CD pipelines, threat modeling, secure code review, integration and architecture review, secure configuration hardening, cloud security review, IoT security assessment, and penetration testing across web, mobile, API, and thick applications. Its portfolio is organized into three tiered subscription packages: the Basic "DevSecOps As Service" tier providing SAST, DAST, SCA, IAST, and triage tooling; the Advanced "AppShield 360" tier adding training and assurance services (penetration testing, red teaming, code review, threat modeling, integration review, secure configuration review); and the Premium "AppSec Accelerate Program" tier adding application security maturity assessment, strategy and roadmap development, and strategy execution. AppSec monetizes via multi-year subscription contracts on a quote-based pricing model, executing an enterprise field-sales motion complemented by free expert advice consultations booked through Microsoft Outlook and lead generation through its owned AppSecEve event series. The firm is a Certified Black Duck Service Provider in the region, holds strategic partnerships with SPCS, Mobily Business, Makkah Knowledge Company, and First City Company, and operates with an 11-50 employee base.
AppSec firmographics
Firmographics- Name
- AppSec
- Legal name
- AppSec – Application Security Services
- Website
- https://appsec.sa
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- AppSec is a Riyadh-based application security services firm founded in 2009 that provides SSDLC, DevSecOps, and security testing consulting across SAST, DAST, SCA, IAST, and penetration testing to government, banking, fintech, telecom, and retail clients in the Middle East via three tiered subscription packages.
- Ownership category
- akta.pro rank
AppSec industry classification
Industry- Product category
- Application Security Services
- NAICS
- Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI)
- akta.pro secondary industries
- Application Security & DevSecOps Services (BPAKAHAJ), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI), CI/CD & DevSecOps Security (Pipeline, Secrets, IaC Scanning) (HDADACAF), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where AppSec is headquartered
LocationHeadquarters
- HQ city
- Riyadh
- HQ country
- Saudi Arabia
- HQ region
- Middle East
Offices1 record
Markets served
AppSec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Application Security Consulting Services: Professional services revenue model offering security assessments, penetration testing, code reviews, threat modeling, and security training across three tiered packages: Basic (DevSecOps As Service), Advanced (AppShield 360), and Premium (AppSec Accelerate Program). Services include both project-based assessments and ongoing managed security services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Basic Package - DevSecOps As Service: Entry-level package providing SAST, DAST, SCA, IAST tools and triage service |
| Subscription | Multi-year contract | Advanced Package - AppShield 360: All Basic services plus application security training and assurance services |
| Subscription | Multi-year contract | Premium Package - AppSec Accelerate Program: All Advanced services plus maturity assessment, strategy development, and implementation |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
AppSec product offering
Product offeringCore offering
AppSec delivers application security consulting and testing services across the entire secure software development lifecycle (SSDLC). It builds and implements SSDLC frameworks, integrates DevSecOps into CI/CD pipelines, and performs security testing using SAST, DAST, SCA, and IAST tools, complemented by penetration testing, threat modeling, secure code review, API security design review, cloud security review, IoT security assessment, and an Application Security Triaging Service. Services are packaged in three tiers — Basic (DevSecOps As Service), Advanced (AppShield 360), and Premium (AppSec Accelerate Program) — targeting organizations that need to embed security into digital transformation initiatives.
Product overview
AppSec is an application security services company offering a tiered portfolio of security testing and consulting services. The core offerings consist of three packages: DevSecOps As Service (Basic tier) providing automated security testing tools; AppShield 360 (Advanced tier) adding training and comprehensive assurance services; and the AppSec Accelerate Program (Premium tier) providing strategic assessment and implementation support. The company also offers individual consulting services including SSDLC framework development, threat modeling, penetration testing, and security assessments for cloud and IoT environments.
Differentiator
Problem solved
Functional benefit
Brands
- DevSecOps As Service: Basic package offering SAST, DAST, SCA, IAST, and Triage Service
- AppShield 360
- AppSec Accelerate Program
Products and services
- DevSecOps As Service Foundational DevSecOps service providing automated security testing tools including SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), SCA (Software Composition Analysis), and IAST (Interactive Application Security Testing), along with an Application Security Triaging Service. Targeted at organizations beginning their DevSecOps journey.
- AppShield 360 Advanced security package that includes all DevSecOps As Service capabilities plus application security training and assurance services, including penetration testing, red teaming, code review, threat modeling, integration review, and secure configuration review. Targeted at organizations seeking comprehensive security assurance beyond tooling.
- AppSec Accelerate Program Premium strategic package encompassing all AppShield 360 capabilities plus Application Security Maturity Assessment, Application Security Strategy & Roadmap development, and Application Security Strategy Implementation support to help organizations build comprehensive application security programs. Targeted at organizations seeking strategic transformation of their application security posture.
- Application Security Triaging Service Service designed to enhance AST tool effectiveness through continuous tuning, false positive analysis, and finding prioritization. Includes AST tool administration, SLA/KPI development, triaging process definition, and scan analysis reporting. Targeted at organizations operating AST tooling that need help reducing noise and operationalizing findings.
- Application Security Services Comprehensive application security consulting services covering the full secure software development lifecycle, including SSDLC framework development, API security design review, software supply chain security, threat modeling, secure code review, integration security review, secure configuration hardening, cloud security review, IoT security assessment, and penetration testing. Targeted at government, banking, fintech, and other enterprise sectors undergoing secure digital transformation.
Companies that use AppSec
Customer profileNamed customers7 records
Segments4 records
Ideal customer profiles3 records
AppSec technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
AppSec partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered minor and core.
- Gulf-ITminorExhibition partner for AppSecEve25 event, showcasing application security tools and services.
- IriusRiskminorExhibition partner for AppSecEve25 event, showcasing threat modeling and risk management solutions.
- WallarmminorExhibition partner for AppSecEve25 event, showcasing API security solutions.
- Positive TechminorExhibition partner for AppSecEve25 event.
- SecuronixminorExhibition partner for AppSecEve25 event, showcasing security analytics solutions.
- CertesminorExhibition partner for AppSecEve25 event, showcasing network security solutions.
- Black DuckcoreAppSec achieved certified implementation service provider status by Black Duck, a leading software composition analysis company. This partnership enables AppSec to deliver world-class application security solutions using Black Duck tools and reinforces credibility among customers, industry peers, and potential partners.
- SPCScoreMemorandum of Understanding signed between SPCS and AppSec during BHMEA24 event to strengthen collaboration in providing application security solutions, delivering and implementing application testing services.
- Makkah Knowledge CompanyminorExploring collaboration opportunities with Makkah Knowledge Company on application security initiatives.
- Mobily BusinesscorePartnership agreement with Mobily Business to provide application security services, penetration testing, and IoT security services. Collaboration aims to deliver comprehensive security services to Mobily Business customers.
- First City CompanyminorCollaboration agreement signed to boost application security capabilities with First City Company.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
AppSec competitors and assessment
Company assessmentBroad incumbents
- Deloitte (Cyber Risk): Big-4 advisory firm with a sizable application security and DevSecOps practice serving global banking, government, and telecom clients. Direct competitor on large Saudi enterprise transformation bids.
- Optiv Security: Large US-focused cybersecurity solutions and services provider spanning advisory, integration, and managed AppSec. Comparable as a broader incumbent offering overlapping AppSec/DevSecOps services to enterprise customers.
- Accenture Security: Global consulting giant with a dedicated cybersecurity practice covering application security, DevSecOps transformation, and managed security services. Competes with AppSec on enterprise Saudi digital transformation mandates.
Direct peers
- Bishop Fox: US-based boutique cybersecurity consultancy focused on application security, penetration testing, and red teaming. Closely mirrors AppSec's tiered services model and enterprise customer base across financial services and technology.
- NCC Group: UK-listed cybersecurity consultancy with a substantial application security and software assurance practice. Directly comparable to AppSec as a specialist services firm offering AppSec testing, DevSecOps advisory, and code review for enterprise clients.
- NetSPI: Application security and penetration testing specialist offering tiered managed testing, vulnerability management, and DevSecOps advisory. Comparable to AppSec in service packaging, target verticals, and delivery model.
- Trustwave: Global cybersecurity services firm with a strong application security and penetration testing portfolio. Comparable to AppSec in offering managed application security testing, code review, and consulting for enterprise and government clients.
Emerging players
- Veracode: Application security testing vendor offering SAST, DAST, SCA, and IAST on a SaaS platform with growing managed services. Comparable to AppSec in the tooling stack it deploys (SAST/DAST/SCA/IAST) and overlapping customer base.
- Checkmarx: Enterprise application security platform vendor covering SAST, SCA, IaC scanning, and DevSecOps tooling. Comparable to AppSec as a leading AppSec technology vendor whose tools underpin much of the regional AppSec services market.
Regional players
- Spire Solutions: Leading Middle East-focused cybersecurity value-added distributor and services provider. Comparable to AppSec as a regional specialist delivering application security and DevSecOps solutions across the GCC, including Saudi Arabia.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
AppSec social profiles
Digital presenceAppSec financial estimates
Financial estimateRevenue estimate
Valuation estimate
AppSec leadership team
Management profileNumber of profiles
Profiles1 record
AppSec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
AppSec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about AppSec
What does AppSec do?
AppSec delivers application security consulting and testing services across the entire secure software development lifecycle (SSDLC). It builds and implements SSDLC frameworks, integrates DevSecOps into CI/CD pipelines, and performs security testing using SAST, DAST, SCA, and IAST tools, complemented by penetration testing, threat modeling, secure code review, API security design review, cloud security review, IoT security assessment, and an Application Security Triaging Service. Services are packaged in three tiers — Basic (DevSecOps As Service), Advanced (AppShield 360), and Premium (AppSec Accelerate Program) — targeting organizations that need to embed security into digital transformation initiatives.
Is AppSec a public or private company?
AppSec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was AppSec founded?
AppSec was founded in 2009. It employs 11 to 50 people.
Where is AppSec based?
AppSec is headquartered in Riyadh, Saudi Arabia, in the Middle East region.
How does AppSec make money?
One revenue line is on record: application Security Consulting Services.
Who are AppSec's main competitors?
Broad incumbents on record are Deloitte (Cyber Risk), Optiv Security and Accenture Security. Direct peers are Bishop Fox, NCC Group, NetSPI and Trustwave. Emerging players are Veracode and Checkmarx. Spire Solutions is listed as a regional player.
Does AppSec have an API?
No public API is recorded for AppSec.
What industry is AppSec in?
AppSec's product category is Application Security Services. Its primary akta.pro industry code is BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security), with a secondary code of BPAKAHAJ, Application Security & DevSecOps Services. Its NAICS code is 54151 and its SIC code is 7371.