Licensed by the Singapore regulator, and verifiable in a minute

AppSecure holds a penetration testing service licence issued by the Cybersecurity Services Regulation Office (CSRO) under the Cybersecurity Act 2018 — and appears on the CSRO list of licensed business entities. Everything on this page can be checked against that public register.

Operating under
Cybersecurity Act 2018
CSRO licensing
MAS TRM
PDPA
A bunch of different types of web apps.
CSRO · Cybersecurity Services Regulation Office

Licensed by the regulator to test in Singapore

Penetration testing is a licensable service under the Cybersecurity Act 2018, administered by CSRO. Engaging an unlicensed provider is the buyer's exposure too — here is our licence record, as it appears on the CSRO register.

REPUBLIC OF SINGAPORE
Cybersecurity Act 2018
VERIFIED ACTIVE
REPUBLIC OF SINGAPORE
CS/PTS/C-202509-003
License
APPSECURE SECURITY VENTURES PTE. LTD.
UEN
202128399R
Licensable activity
Penetration testing service
Statutory, not self-declared

The licence is granted and revocable by the regulator, with conditions on conduct, records and reporting.

Officer accountability per engagement

A named responsible officer is recorded in your engagement letter and answerable for the work.

Status changes notified in 2 days

Any change to licence status is put in writing, with your right to pause testing until resolved.

Why it matters

Licensing is risk transfer, not decoration

Regulatory exposure

Contracting an unlicensed tester in Singapore puts the buyer in scope of the breach, not just the vendor.

Faster onboarding

Pre-answered questionnaires and a ready evidence pack cut weeks out of vendor-risk review.

Audit-ready evidence

Reports and attestation letters slot straight into SOC 2, ISO 27001 and MAS TRM files.

Data you can account for

Encrypted evidence, defined retention, certified destruction — and a written trail for each step.

How it Works

How a licensed engagement runs

Request a Penetration Test
STEP 1
Scope under the licence

Rules of engagement, target inventory and authorisation are recorded against the licensed activity before testing starts.

A black and white photo of a clock.
STEP 2
Assign screened testers

Named consultants, vetted and certified, working under the responsible officer for the duration.

STEP 3
Test with evidence control

Manual, hacker-led testing with every artefact captured into an encrypted, access-controlled evidence store.

STEP 4
Report to framework

Findings mapped to MAS TRM, ISO 27001, SOC 2 and PCI DSS, with an attestation letter for your customers.

STEP 5
Retain, then destroy

Retention runs to the agreed window, then destruction is certified in writing and logged against the engagement.

Testimonial

People Love What We Do

Service Used:
Penetration Testing

The team at AppSecure not only finds security loopholes but also provides detailed action plans to fix the vulnerabilities found in the system.

Mukund
Mukund
Director Platform @Atlan
Service Used:
Penetration Testing

They pointed out a bunch of high and critical vulnerabilities, helping us meet our goals and making our applications and APIs more secure.

Souvik Dutta
Souvik Dutta
CTO & Country Head @Signeasy
Service Used:
Penetration Testing

They have been instrumental in making ClearTax more secure, and I will highly recommend them to any company that takes security seriously.

Ankit Solanki
Ankit Solanki
Co-Founder @Cleartax
Service Used:
Penetration Testing

We have been working with AppSecure for 1 Year now and the team has helped us to make sure that our security is never compromised.

Hari
Hari
Vice President Engineering @Near
Service Used:
Product Security

AppSecure is like our extended security team. The AppSecure team is very patient in pointing out the non-trivial security bugs in our systems.

Srirang
Director Of Technology @Slice
Service Used:
Product Security

I have been impressed with AppSecure team's deep expertise on the OWASP areas, and the team does quite a thorough job on each of the engagements and provide detailed and timely reports.

Daniel Wong
Daniel Wong
CISO @Skyflow
Service Used:
Penetration Testing

They gave great feedback that improved the security of our products immensely and allowed us to focus on product development.

Keith Morris
Keith Morris
Managing Director @Tanooki Labs
Service Used:
Penetration Testing

They have been instrumental in making ClearTax more secure, and I will highly recommend them to any company that takes security seriously.

Ankit Solanki
Co-Founder @Cleartax
Service Used:
Penetration Testing

The team at AppSecure not only finds security loopholes but also provides detailed action plans to fix the vulnerabilities found in the system.

Mukund
Director Platform @Atlan
Service Used:
Penetration Testing

The team is also very flexible to learn about new technologies quickly to do a great job pentesting in spite of limited documentation.

Daniel Wong
CISO @Skyflow
Service Used:
Penetration Testing

They pointed out a bunch of high and critical vulnerabilities, helping us meet our goals and making our applications and APIs more secure.

Souvik Dutta
CTO & Country Head @Signeasy
Service Used:
Penetration Testing

AppSecure is like our extended security team. The AppSecure team is very patient in pointing out the non-trivial security bugs in our systems.

Srirang
Director Of Technology @Slice
Service Used:
Penetration Testing

We have been working with AppSecure for 1 Year now and the team has helped us to make sure that our security is never compromised.

Hari
Vice President Engineering @Near
Service Used:
Penetration Testing

They gave great feedback that improved the security of our products immensely and allowed us to focus on product development.

Keith Morris
Managing Director @Tanooki Labs
FAQs

Questions You May Have

Can we verify the licence independently?

Yes. CSRO publishes a list of licensed business entities at csro.gov.sg — download it and search for APPSECURE SECURITY VENTURES PTE. LTD. (UEN 202128399R) or licence number CS/PTS/C-202509-003. The signed licence PDF is in the compliance pack, and we can arrange written confirmation if your policy requires it.

What is the difference between the Licence Summary and the Official Licence?

Both describe the same licence, CS/PTS/C-202509-003. The Licence Summary is a designed one-page overview — number, activity, status and validity, with a first-page preview — built for a fast read during vendor review. The Official Licence is the complete government-issued document, including licence conditions and responsible officer particulars, and is the version your compliance file should hold.

How is our test data stored, retained and destroyed?

Evidence is encrypted at rest and in transit and access-controlled to the assigned team. Retention follows the licence conditions and your DPA — 90 days by default — after which destruction is certified in writing. Proof-of-concept artefacts never leave the evidence store.

What happens if the licence lapses mid-engagement?

Renewals are tracked centrally and filed well ahead of expiry. Our MSA commits us to notify you in writing of any change to licence status within two business days, with your right to pause testing until it is resolved.

What insurance and liability cover do you carry?

Professional indemnity and cyber liability cover are in place, with certificates of insurance issued on request. Limits and governing jurisdiction are confirmed in the MSA; higher limits can be arranged before signature.

Take the Compliance Evidence with you