Skip to content
soc2pentest

A plain-English reference on SOC 2 for European vendors: who may issue the report, and what the penetration test is actually for.

Run the gap finder→
  • 01Who issues what
  • 02The pentest question
  • 03Gap finder
  • 04In Europe
  • 05Guides
Home

Privacy policy

Updated 13 September 2026

Operator and scope

soc2pentest.org is a free reference operated by SEQ SIA (OffSeq), registration number 40203410806, Lastādijas iela 12 k-3, Riga, LV-1050, Latvia. The site has no user accounts, no newsletter, no contact form and no comments.

The readiness gap finder

The worksheet runs entirely in your browser. The categories you select and the answers you mark are held in page memory for as long as the page is open. They are not sent to OffSeq, not written to local storage or any cookie, not included in analytics events, and not added to outbound links. Closing or reloading the page discards them. The worksheet is educational: it does not inspect your accounts, your infrastructure or your evidence.

Technical requests and traffic measurement

Serving a page through Cloudflare involves technical request data, including an IP address, browser headers, the requested URL and the request time. These data support delivery, security and operation of the site. Cloudflare may set its own security cookies; those are separate from the site application.

The site sends page views and clicks on OffSeq service and contact links to our self-hosted Plausible service at in.ainalytic.net. Events include the site domain, the public page address, limited campaign parameters and the referring site's origin when available. A link-click event adds only the destination path and a static placement label such as header, hero or gap-finder. Worksheet answers and results are never sent. The application does not set analytics cookies or a persistent visitor identifier; the collector receives technical network information with the request. Cookieless measurement is still data processing.

Measurement is disabled when the browser signals Do Not Track or Global Privacy Control, when the local-storage preference plausible_ignore is set to true, and for previews, local development and recognized automation. OffSeq links may carry static referral labels identifying this resource and the link placement; those labels never contain worksheet answers.

Purpose, legal basis and retention

We use technical request data to operate and secure the site, and page-view and link-click statistics to understand how the resource is used and how much interest there is in OffSeq services. The operator's stated legal basis for these purposes is legitimate interests under Article 6(1)(f) GDPR. Hosting and infrastructure providers process requests on our behalf; the analytics service is self-hosted. Data are kept only as long as needed for those purposes and any applicable legal obligation. The operator's privacy policy explains its retention criteria, providers and transfer safeguards.

Contact and external links

If you email support@offseq.com, we receive the address, the message and anything you choose to include, so that we can reply. Correspondence is retained while it is needed to handle the enquiry or the business relationship. OffSeq service links and the sources cited in the guides take you to sites with their own privacy notices.

Your rights

Subject to the conditions in the GDPR you may request access, correction, deletion, restriction or portability, and object to processing. Contact support@offseq.com. You may also complain to Latvia's Data State Inspectorate or to the supervisory authority where you live or work. The cookie and browser-storage notice covers what is and is not stored in your browser.

soc2pentest

soc2pentest.org is a free reference on SOC 2 for European vendors: what the report is, who is allowed to issue it, where the expectation of a penetration test really comes from, and how SOC 2 sits alongside ISO/IEC 27001 and the ISAE assurance standards.

Guides

  • Does SOC 2 require a pentest?
  • Who can issue a SOC 2
  • SOC 2 or ISO 27001
  • Scope, timing and the report

Professional help

  • Readiness and gap assessment
  • Penetration testing
  • Scope an engagement
  • Talk to OffSeq

Information

  • About
  • Privacy policy
  • Cookies and browser storage

soc2pentest.org is a free reference maintained by the OffSeq security team. OffSeq is not a CPA firm and does not perform SOC examinations or issue SOC reports.

SOC 1, SOC 2 and SOC 3 are registered trademarks of the AICPA. This site is not affiliated with, endorsed by or accredited by the AICPA, the IAASB or ISO.

Operated by SEQ SIA · Riga, Latvia