I wonder what they mean by security testing? What exactly are they testing and how?
BTW given that there's no security patches released for 5.2 anymore (while bugs are still being found and published of course) - their understanding of security is certainly unorthodox.