
Siemens AG Issues €330M Tokenised Bond on Blockchain — Audited by Softstack
Softstack audited the smart contracts for Siemens AG’s €330M tokenised bond, settled via central bank money on institutional blockchain rails.
Everyone can talk. We prefer to let our work and our clients speak for us. Get to know us and see the difference.
All of our team members are full-time employees — no freelancers, no outsourcing, no uncontrolled risks.
No hidden fees or vague estimates. We mostly work on fixed-price projects and deliver what we promise, without excuses.
Since 2017, we have been building cutting-edge solutions in Web3, AI, and enterprise-grade digital solutions.
Headquartered and operating fully in Germany, ensuring high standards, data protection, and reliability.
Clear updates, short response times, and full transparency throughout the project.
You work directly with our leadership. The CEO is personally involved, and we operate with a lean, effective scrum-based approach for speed and clarity.
Rated by clients on
You'll find the following service aspects in our offer.
Map your VARA-licensed VA Activities, critical systems, custody architecture, and smart contracts that must be covered under the Technology and Information Rulebook.
Define annual vulnerability assessments and penetration tests, plus smart contract effectiveness and robustness reviews before new systems, applications, or products go live.
Run qualified, independent assessments across infrastructure, applications, and relevant smart contracts. Document results so evidence is ready if VARA requests it.
If VARA requires threat-led penetration testing, structure intelligence-led red teaming of critical functions with suitable external testers and controlled production testing.
Track findings to closure with formal remediation evidence. Package reports and retest notes for internal governance and VARA inspection readiness.
Under the VARA Technology and Information Rulebook, VASPs must engage a qualified, independent third-party auditor for vulnerability assessments and penetration testing at least annually, and before introducing new systems, applications, or products. Where relevant to VA Activities, that includes comprehensive smart contract audits of effectiveness, enforceability, and robustness. Results must be available to VARA on request.
VARA may notify a VASP to carry out advanced TLPT where it is necessary and proportionate to the VASP’s risk profile and criticality. TLPT is not the same as a standard annual pentest. It is intelligence-led adversarial testing of critical functions, typically with strict tester suitability, insurance, and confidentiality requirements.
Scope follows the licence and Rulebook: annual cadence, pre-change testing, smart contract coverage where relevant, documented evidence for inspection, and optional TLPT if notified. We design the work so security findings and compliance artefacts stay aligned.
Yes. We audit on-chain components and test off-chain apps, APIs, and infrastructure that support exchange, custody, brokerage, and related VA Activities. That combination matches how most VASPs actually operate.
At least once a year as a baseline, and before major product or system launches. After material architecture changes, retest the affected surfaces. If VARA notifies TLPT, plan a longer programme with threat intelligence, red teaming, and remediation windows.