Evidence-Led Cybersecurity
Think like an attacker.
Defend like one too.
Penetration testing, red teaming and NIS2 / DORA readiness for organisations across the EU.
We verify security through attacker-led testing, clear evidence and practical remediation guidance.
Reply within 24 hours · Re-testing available for every engagement
-
OffSeq found issues our previous audits never surfaced — and explained exactly how to fix them.
-
A genuine attacker’s perspective. The red team report changed how we prioritize security investment.
-
Clear, pragmatic and fast. They treat our risk like it’s their own.
Security claims should be supported by evidence.
03 / 07The specialists who conduct our client engagements also perform independent vulnerability research and build the tools used in our work. The results below are publicly verifiable.
- 01
Cross-instance configuration poisoning in X-Road
X-Road Security Server (< 7.8.2)
X-Road Security Servers wrote federated global-configuration parts to disk based on the ecosystem identifier carried inside each part, without verifying it matched the actual source. A malicious federation partner could serve a SHARED-PARAMETERS part naming a victim ecosystem — signed with the victim’s own key — and overwrite its authoritative trust configuration, gaining persistent control and the ability to impersonate any of the victim’s members and Security Servers.
Insufficient verification of data authenticity (CWE-345, CWE-346)
CVSS 8.0 High GHSA-c5gr-pcm6-828r 2026 - 02
Command injection fixed in Estonia’s national eID software
DigiDoc4 — Estonia’s official eID signing application
DigiDoc4’s file-manager integration constructed shell commands using unsanitised filenames. A specially crafted filename could execute arbitrary code when a user selected the file for signing or encryption. The issue affected software used for legally binding electronic signatures.
OS command injection (CWE-78)
Critical 2026 - 03
SWQL injection in SolarWinds Platform
SolarWinds Platform (≤ 2024.1 SR 1)
A query-language injection vulnerability allowed an attacker to manipulate back-end database queries in the SolarWinds Platform. It was identified during penetration testing for the NATO Communications and Information Agency.
SQL / SWQL injection (CWE-89)
CVSS 7.5 High CVE-2024-28996 2024
A European cybersecurity company, verified in public
OffSeq is an EU-based cybersecurity company working with organizations across Europe, backed by public evidence, international certifications and EU-wide regulatory expertise.
- 01
Evidence in the public record
Credited CVEs and coordinated disclosures in software used across Europe and beyond — from national eID systems to enterprise and data-exchange platforms.
See results - 02
European competence network
Connected to the European Cybersecurity Competence Centre (ECCC) network through its national coordination centres across the EU.
EU network - 03
NIS2, DORA & GDPR expertise
Compliance audits, gap assessments and threat-led testing aligned with the EU requirements relevant to your organization.
EU regulation
How our approach differs
We combine manual attacker-led testing with reproducible evidence and practical remediation guidance.
- 01
Compared with generic audits
ElsewhereA compliance checklist with limited technical validation.
With OffSeqTesting based on relevant attack paths, supported by evidence of potential business impact.
- 02
Compared with automated scanners
ElsewhereLarge volumes of unverified results that your team must triage.
With OffSeqManual validation by qualified specialists, focused on findings that materially affect risk.
- 03
Compared with unproven providers
ElsewhereA report from a provider whose qualifications may be difficult to verify.
With OffSeqAn EU-based team whose work is verifiable in the public record, operating under NDA and offering re-testing to verify remediation.
What to order
28 servicesChoose the group that matches your situation — from security testing to monitoring, governance and EU regulatory readiness.
- 01
Security Testing
When you need to know how you’d actually be breached. Security Audits · Red Team & Adversary Emulation · Social Engineering Assessment · Purple Teaming · Attack Surface Management · DORA Threat-Led Penetration Testing · Smart Contract & Web3 Security Audit · Ransomware Readiness Assessment ×8 - 02
Application, API & AI Security
When you ship code, APIs or AI. AI & LLM Security · API Security Testing · Secure Code Review & SAST · DevSecOps & Secure CI/CD · Mobile App Security Testing · Supply Chain Security & SBOM · Threat Modeling & Secure Design · Performance & Load Testing ×8 - 03
Cloud Security, Monitoring & Response
When the concern is your live environment. Cloud Security & Posture Assessment · Kubernetes & Container Security · Proactive Security Monitoring · Incident Response & Digital Forensics · OSINT & Open Data Analysis ×5 - 04
Governance, Risk & Compliance
When a regulator, auditor or board is asking (NIS2 / DORA / ISO). CISO-as-a-Service · NIS2 & ISO 27001 Readiness · DORA Compliance & Resilience Testing · Data Protection Impact Assessment · Security Policy & Procedure Development · Security Technology Selection & Implementation · Employee Cybersecurity Awareness Training ×7
What we test
We assess the technical, human and physical attack surfaces available to an adversary. Each row links to the relevant service; testing depth ranges from a focused assessment to a full-scope red-team engagement.
| Surface ╲ Test | REC Reconnaissance & ASM | VA Vulnerability assessment | PT Penetration test | RT Red team | HR Hardening review | MON Continuous monitoring |
|---|---|---|---|---|---|---|
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Core capability | Hardening review: Core capability | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Penetration test · Red team · Hardening review Available when included in scope Continuous monitoring Web applications & APIs | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Available when included in scope | Red team: Available when included in scope | Hardening review: Available when included in scope | Continuous monitoring: Core capability | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Continuous monitoring Available when included in scope Penetration test · Red team · Hardening review External attack surface | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Available when included in scope | Hardening review: Core capability | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Penetration test · Hardening review Available when included in scope Red team · Continuous monitoring Cloud environments & containers | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Core capability | Hardening review: Available when included in scope | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Penetration test · Red team Available when included in scope Hardening review · Continuous monitoring Internal network & AD | ||||||
| Reconnaissance & ASM: Available when included in scope | Vulnerability assessment: Core capability | Penetration test: Available when included in scope | Red team: Out of scope | Hardening review: Core capability | Continuous monitoring: Core capability | |
| Core capability Vulnerability assessment · Hardening review · Continuous monitoring Available when included in scope Reconnaissance & ASM · Penetration test Out of scope Red team Source code & software supply chain | ||||||
| Reconnaissance & ASM: Available when included in scope | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Core capability | Hardening review: Core capability | Continuous monitoring: Available when included in scope | |
| Core capability Vulnerability assessment · Penetration test · Red team · Hardening review Available when included in scope Reconnaissance & ASM · Continuous monitoring AI / LLM systems | ||||||
| Reconnaissance & ASM: Available when included in scope | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Available when included in scope | Hardening review: Core capability | Continuous monitoring: Out of scope | |
| Core capability Vulnerability assessment · Penetration test · Hardening review Available when included in scope Reconnaissance & ASM · Red team Out of scope Continuous monitoring Mobile applications | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Out of scope | Penetration test: Core capability | Red team: Core capability | Hardening review: Available when included in scope | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Penetration test · Red team Available when included in scope Hardening review · Continuous monitoring Out of scope Vulnerability assessment People (social engineering) | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Available when included in scope | Penetration test: Core capability | Red team: Core capability | Hardening review: Available when included in scope | Continuous monitoring: Out of scope | |
| Core capability Reconnaissance & ASM · Penetration test · Red team Available when included in scope Vulnerability assessment · Hardening review Out of scope Continuous monitoring Wireless networks & physical security | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Available when included in scope | Penetration test: Available when included in scope | Red team: Available when included in scope | Hardening review: Available when included in scope | Continuous monitoring: Out of scope | |
| Core capability Reconnaissance & ASM Available when included in scope Vulnerability assessment · Penetration test · Red team · Hardening review Out of scope Continuous monitoring OT, IoT & embedded systems | ||||||
- Core capability
- Available when included in scope
- Out of scope
A structured process, not just a scan
A transparent, repeatable process that turns an attacker’s view of your organization into measurable security improvements.
Reconnaissance
Map the attack surface relevant to your organization, including assets, exposure, people and third parties.
Assessment
Assess and test through vulnerability analysis, penetration testing, social engineering and red team simulation.
Reporting and remediation
Severity-rated findings with business impact, proof, and a prioritised remediation roadmap.
Resilience
Continuous monitoring, incident-response readiness and compliance — so gains hold over time.
Security testing in practice
Engagements, venues and equipment — from classified cyber ranges to security-community events.
Helpful tools
- 01 Scope a test Create a scoped brief in one minute
- 02 NIS2 / DORA scope check Check whether the regulations apply to your organization
- 03 Security maturity assessment Assess your organization across six domains
-
See what the report includes
A complete sample report with evidence-backed findings from Critical to Low, CVSS scoring, OWASP mapping and a prioritized remediation plan. -
Latvia’s 2026 Threat Picture: 6 Moves to Make This Quarter
CERT.LV recorded 757,286 compromised devices in Latvian cyberspace in Q1 2026, the highest figure reported to date. Most were classified as configuration weaknesses. This briefing turns the published trends into six practical priorities for the quarter. Jun 2026 · 11 pages · 7 min read
Tools developed and used by OffSeq
OffSeq operates its own security platform. The same threat data and tools used in client engagements are also available directly to customers.
- 01
OffSeq Threat Radar
Vulnerability intelligence prioritised by relevance. - 02
OffSeq Mirage
Real-time intelligence from honeypot telemetry. - 03
OffSeq Pulse
Endpoint posture and device control, hosted in the EU. - 04
OffSeq Breach
Credential-exposure monitoring for your domains. - 05
OffSeq Guard
Web-exposure analysis with daily change monitoring. - 06
OffSeq Veil
Browser-based encryption and steganography.
Do not just read about attacks. Respond to one.
Enter a 3D office and respond to a phishing email, scam call or AI prompt-injection attempt. Choose a simulation and test your judgment.
Certified to international standards
-
OSCP OffSec
-
Lead Pen Test Professional PECB -
ISO/IEC 27001 Senior Lead Auditor PECB -
Certified Information Systems Auditor ISACA -
Red Team Operations Clarified Security
-
Critical Information Infrastructure Protection NATO CCDCOE
-
Web Applications Attack & Defence NATO CCDCOE
-
IT Systems Attack & Defense CybExer
-
Cybercrime CEPOL -
Cyber Bite: Darkweb CEPOL -
OSINT – Cryptocurrencies CEPOL -
Security Awareness: Privileged Accounts SANS
What people say about working with us
At Trace.Space, security has always been a core priority — not an afterthought. As an AI platform trusted by engineering teams building regulated products in automotive, aerospace, medical and defense industries, we hold ourselves to the highest standards. Because we are shipping features at an incredible pace, we recognized that we needed a security partner capable of scaling at our velocity. That is exactly why we partner with OffSeq. We don’t want a standard checkbox compliance vendor; we want an elite partner to help us continuously take our security posture to the next level. Instead of slowing us down, they seamlessly integrate with our fast-moving engineering team, providing proactive, high-level insights that let us fortify our systems in real time as we grow. Working with OffSeq consistently proves that when you are building fast, having a world-class security partner in your corner is the best way to stay ahead of the curve.
We’ve had the pleasure of working with SEQ SIA (led by Nils Putniņš) on multiple information security engagements at Printful, ranging from targeted penetration testing to in-depth evaluations of our platform’s security maturity. In every project, SEQ SIA has demonstrated a rare combination of technical precision, strategic thinking, and professionalism. Most recently, during a performance and security audit of one of our core systems — used daily by thousands of employees and clients — SEQ SIA delivered beyond expectations. Their structured methodology, clear communication, and actionable insights directly contributed to increased system reliability, scalability, and resilience. SEQ SIA has become a trusted security partner, and we highly value the clarity and confidence they bring to complex security challenges.
I had some expectations when we signed up with OffSeq. I was expecting some social engineering, routine web works to see our loopholes. Instead, they dug with passion, and they dug deep. They found holes me and my IT team were astonished to hear about. They worked from the heart and in high quality.
We confirm that SIA “SEQ” conducted three information system security audits in 2025. The audits were carried out professionally and in full compliance with the contractual requirements. We are satisfied with the service provided. — State Emergency Medical Service of the Republic of Latvia (NMPD).
Ar šo apliecinām, ka SIA “Codex” ir veiksmīgi sadarbojies ar SIA “SEQ” un tā speciālistu Nilu Putniņu vairāku nozīmīgu projektu ietvaros. Sadarbības laikā esam augsti novērtējuši SIA “SEQ” sniegto pakalpojumu kvalitāti, profesionalitāti un atbildīgo pieeju. Visas saistības veiktas norunātajos termiņos un augstā kvalitātē. Nils Putniņš ir apliecinājis sevi kā augstas klases ekspertu informācijas sistēmu drošības un kiberdrošības jomā.
The OffSeq team collaborated with the LG team to identify and resolve several high-severity vulnerabilities within LG’s products and services promptly. We appreciate their dedication to helping us improve the security of LG Electronics.
In Eleving Group security resilience is at the core of what we do across 17 markets and more than 1.8M customers. Partnering with OffSeq on a red team engagement gave us a genuine adversarial perspective that went well beyond a traditional penetration test. Their team demonstrated deep technical expertise, operated with realism and precision, and communicated findings in a way that was both clear and actionable. We came away more resilient and better informed.
Working with OffSeq has been a solid experience from day one. They’ve helped us with red teaming, penetration testing, and assessments — not just for our own systems but also for some of our clients. What stands out is their practical approach — no fluff, just clear findings and actionable recommendations. They know how to dig deep, but they also understand how to communicate technical risks in a way that makes sense to different stakeholders. We’ve come to trust them as a reliable extension of our security team, and we’re looking forward to continuing the collaboration.
We export to over 20 countries, so the security of our systems and client data isn’t something we take lightly. OffSeq ran a black-box audit that showed us exactly where we stood — no sugarcoating, just an honest picture from a real attacker’s perspective. The report worked for both our IT team and our board, which is rare. Really solid work all around.
We were working with SEQ and their expert Nils Putniņš for security testing of our systems and we are happy with the results and their fast response time. We recommend SEQ and are looking forward to a long-term collaboration.
SEQ and specialist Nils Putniņš performed a security audit for a project in development at Jāņa Sēta in June 2023. We are very satisfied with the test results, which helped improve the system’s security. The work was done quickly and to a high standard. We plan to keep working with SEQ.
Frequently asked questions
What are your credentials as a cybersecurity provider?
OffSeq is an EU-based cybersecurity company working with organizations across Europe. Our credentials are public: credited CVEs and coordinated vulnerability disclosures; OSCP, CISA and PECB ISO/IEC 27001 Lead Auditor certifications held by the specialists who perform the work; and testing aligned with EU regulation such as NIS2, DORA and GDPR.
Will I get proof, or just a scanner dump?
Every finding is manually reproduced and assessed by severity and business impact. The report includes supporting requests, responses, payloads and specific remediation guidance. A complete sample report covering findings from Critical to Low is available on our sample-report page.
How quickly do you report critical findings?
Immediately after confirmation. Critical findings are reported as soon as they are verified, allowing remediation to begin before the final report is delivered.
Do you verify that our fixes actually worked?
Yes. A re-test is available on every engagement: we re-check each remediated finding and update its status, so you get closure, not just a list of problems.
Which regions and organization sizes do you serve?
We work with organizations across the Baltics, Scandinavia and the wider EU, from scale-ups to public institutions and large enterprises. Each engagement is scoped to the organization’s risks and timeline rather than a fixed package.
Do we need a designated cybersecurity manager under NIS2?
Organizations within the scope of NIS2 or applicable national cybersecurity law may be required to designate a person responsible for cybersecurity. Our CISO-as-a-Service can provide qualified leadership and support required reporting without the need to hire a full-time CISO.
How do you help with NIS2, DORA and ISO 27001 compliance?
We determine which obligations apply, assess gaps against the relevant controls and provide a prioritized remediation plan and evidence package. The assessment is grounded in realistic attack paths rather than a generic checklist. For DORA, we can also provide TIBER-EU-aligned threat-led penetration testing.
Define the scope of an engagement
Tell us what you need to protect. We will explain how we would test it and how to strengthen its defenses. We reply within 24 hours.