
Siemens AG Issues €330M Tokenised Bond on Blockchain — Audited by Softstack
Softstack audited the smart contracts for Siemens AG’s €330M tokenised bond, settled via central bank money on institutional blockchain rails.
Everyone can talk. We prefer to let our work and our clients speak for us. Get to know us and see the difference.
All of our team members are full-time employees — no freelancers, no outsourcing, no uncontrolled risks.
No hidden fees or vague estimates. We mostly work on fixed-price projects and deliver what we promise, without excuses.
Since 2017, we have been building cutting-edge solutions in Web3, AI, and enterprise-grade digital solutions.
Headquartered and operating fully in Germany, ensuring high standards, data protection, and reliability.
Clear updates, short response times, and full transparency throughout the project.
You work directly with our leadership. The CEO is personally involved, and we operate with a lean, effective scrum-based approach for speed and clarity.
Rated by clients on
You'll find the following service aspects in our offer.
Align white-team control, critical or important functions, production safeguards, and regulator expectations. Confirm whether the driver is DORA designation, VARA notification, or board-level resilience assurance.
Build scenarios from threat actors and TTPs relevant to your sector and organisation, not a generic vulnerability checklist.
Simulate realistic adversary campaigns against live systems supporting critical functions, with strict rules of engagement and continuous risk control.
Replay paths with your blue team to measure detection and response gaps, not only initial compromise.
Deliver attack narratives, control findings, and a remediation plan suitable for internal governance and, where required, competent authority review.
TLPT is advanced, intelligence-led red teaming that simulates how real adversaries would attack your critical or important functions, usually on live production systems. It is deeper and longer than a standard penetration test and focuses on business-critical outcomes, detection quality, and resilience under realistic attack paths.
A standard pentest is typically short, technically scoped, and finding-centric. TLPT is scenario-based, threat-intelligence led, often multi-week, and evaluated against critical functions and detection/response capability. Under DORA, designated entities cannot substitute a generic pentest for required TLPT.
Under DORA, competent authorities identify which financial entities must perform TLPT, typically at least every three years and aligned with TIBER-EU or an equivalent framework. Under VARA, a VASP may be notified to perform TLPT where VARA considers it necessary and proportionate. Softstack helps both designated and preparing organisations.
Yes, when those systems support critical functions. Many CASPs and VASPs need scenarios that cover wallets, key management, trading stacks, APIs, and smart-contract-backed services alongside traditional ICT.
Complete critical function mapping, white-team governance, production safeguards, logging/monitoring readiness, and third-party cooperation where cloud or ICT providers support critical services. Our ICT preparation and DORA/VARA services are designed as upstream steps.