Licensed by the Singapore regulator, and verifiable in a minute
AppSecure holds a penetration testing service licence issued by the Cybersecurity Services Regulation Office (CSRO) under the Cybersecurity Act 2018 — and appears on the CSRO list of licensed business entities. Everything on this page can be checked against that public register.
.webp)


























































Licensed by the regulator to test in Singapore
Penetration testing is a licensable service under the Cybersecurity Act 2018, administered by CSRO. Engaging an unlicensed provider is the buyer's exposure too — here is our licence record, as it appears on the CSRO register.
The licence is granted and revocable by the regulator, with conditions on conduct, records and reporting.
A named responsible officer is recorded in your engagement letter and answerable for the work.
Any change to licence status is put in writing, with your right to pause testing until resolved.
Licensing is risk transfer, not decoration
Contracting an unlicensed tester in Singapore puts the buyer in scope of the breach, not just the vendor.
Pre-answered questionnaires and a ready evidence pack cut weeks out of vendor-risk review.
Reports and attestation letters slot straight into SOC 2, ISO 27001 and MAS TRM files.
Encrypted evidence, defined retention, certified destruction — and a written trail for each step.
Rules of engagement, target inventory and authorisation are recorded against the licensed activity before testing starts.
Named consultants, vetted and certified, working under the responsible officer for the duration.
Manual, hacker-led testing with every artefact captured into an encrypted, access-controlled evidence store.
Findings mapped to MAS TRM, ISO 27001, SOC 2 and PCI DSS, with an attestation letter for your customers.
Retention runs to the agreed window, then destruction is certified in writing and logged against the engagement.
People Love What We Do
Questions You May Have
Can we verify the licence independently?
Yes. CSRO publishes a list of licensed business entities at csro.gov.sg — download it and search for APPSECURE SECURITY VENTURES PTE. LTD. (UEN 202128399R) or licence number CS/PTS/C-202509-003. The signed licence PDF is in the compliance pack, and we can arrange written confirmation if your policy requires it.
What is the difference between the Licence Summary and the Official Licence?
Both describe the same licence, CS/PTS/C-202509-003. The Licence Summary is a designed one-page overview — number, activity, status and validity, with a first-page preview — built for a fast read during vendor review. The Official Licence is the complete government-issued document, including licence conditions and responsible officer particulars, and is the version your compliance file should hold.
How is our test data stored, retained and destroyed?
Evidence is encrypted at rest and in transit and access-controlled to the assigned team. Retention follows the licence conditions and your DPA — 90 days by default — after which destruction is certified in writing. Proof-of-concept artefacts never leave the evidence store.
What happens if the licence lapses mid-engagement?
Renewals are tracked centrally and filed well ahead of expiry. Our MSA commits us to notify you in writing of any change to licence status within two business days, with your right to pause testing until it is resolved.
What insurance and liability cover do you carry?
Professional indemnity and cyber liability cover are in place, with certificates of insurance issued on request. Limits and governing jurisdiction are confirmed in the MSA; higher limits can be arranged before signature.

.webp)
.webp)
.webp)
.webp)

.webp)
.webp)
.webp)

.webp)

.webp)
.webp)
.webp)
.webp)