Offensity GmbH

Germany · www.offensity.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 10 sub-vendors.

Insights

Last updated 2026-08-02 · revision 1

10 direct vendors, 153 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Offensity GmbH demonstrates moderate migration readiness, primarily driven by its modern technological foundation but hampered by significant unknowns. Strengths include a modern and cloud-oriented tech stack, with existing cloud infrastructure (Exoscale, S3-compatible) and applications built on modern, open-source frameworks like Django and Wagtail CMS. These technologies are generally well-suited for migration to various cloud environments and containerized deployments, reducing technical complexity. However, several weaknesses and unknowns impact readiness. Critical financial data (revenue concentration, growth history) is missing, making it impossible to assess the company's capacity to fund a potentially costly migration. Information on specific regulatory compliance obligations and data residency requirements is also absent, which could significantly impact migration strategy and introduce unforeseen complexities. Regarding vendor relationships, despite the 'Total Vendors: 0' entry, the 'Total Services: 8' and diverse vendor countries suggest multiple external dependencies. The 'Vendor Lock-in Risk' is 'Unknown'. While open-source components are used, reliance on Exoscale (A1 Digital's cloud platform) could represent a degree of platform-specific lock-in, even with S3 compatibility, potentially complicating a move to a different cloud provider. There is also no explicit mention of advanced cloud-native patterns like containerization or microservices, which would further enhance migration flexibility. The modern tech stack is a strong enabler, but the substantial unknowns regarding financials, regulatory constraints, data residency, and vendor lock-in prevent a higher readiness score.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

Offensity is a cloud-based SaaS platform (vulnerability scanning delivered via a web dashboard at reporting.offensity.com). SOC2 (System and Organization Controls 2) is highly relevant for cloud service providers, particularly those serving enterprise and regulated-industry customers. While SOC2 is a US-origin framework (AICPA), it is increasingly demanded by enterprise customers globally, including in Europe, as evidence of security controls. The risk is Medium because: (1) Offensity's enterprise and banking customers (e.g., VKB-Bank) may contractually require SOC2 or equivalent assurance, (2) absence of SOC2 or equivalent (e.g., ISO 27001) could be a competitive and contractual risk, and (3) no public SOC2 report has been found.

Evidence: https://www.offensity.com/en/eusa/, https://www.a1.digital/case-studies/vkb-bank-offensity-security/

DSG — Partially Compliant

A1 Digital International GmbH & Co KG is registered in Vienna, Austria, and is the primary legal entity behind Offensity's EUSA. The Austrian DSG (2018, as amended) supplements GDPR in Austria. The privacy policy references both GDPR and the Austrian DSG. A DPO is appointed (datenschutz@a1.digital for Austria). Risk is Medium for the same reasons as BDSG — documented compliance structures exist but independent verification is not publicly available.

Evidence: https://www.a1.digital/privacy-policy/, https://www.offensity.com/en/eusa/

ISO 27001 (source) — Assessment Required

ISO 27001 (Information Security Management System) is highly relevant for Offensity as a cybersecurity SaaS provider. Companies offering security scanning services to enterprise and regulated-industry clients are typically expected to hold ISO 27001 certification as a baseline assurance. The risk is Medium because: (1) the absence of a publicly confirmed ISO 27001 certificate is a gap for a security-focused company, (2) enterprise and banking customers may require it contractually, and (3) NIS2 compliance in Germany and Austria increasingly references ISO 27001 as a recognized standard for risk management measures. However, it is possible that A1 Digital (the parent) holds ISO 27001 certification that covers Offensity's operations.

Evidence: https://www.offensity.com/en/eusa/, https://www.a1.digital/privacy-policy/

Financials

Three-year financials

Financial Resilience Score: 8/10

Offensity is not a standalone legal entity but a SaaS product operated by A1 Digital, a subsidiary of the listed Telekom Austria Group (A1 Group), which is majority-owned by América Móvil. This provides very strong financial backing, with group revenue of approximately €5.36B in FY2024, EBIT of ~€0.95B, and equity of ~€3.8B. The parent is investment-grade, cash-generative, and well-capitalised, insulating Offensity from short-term financial stress. The product itself benefits from a recurring SaaS subscription model, cross-selling opportunities into A1's enterprise/SME customer base across DACH and CEE, and bundling within A1 Digital's broader cybersecurity portfolio (Security Assessment, NIS2 consulting, EDR, cloud backup). However, no standalone P&L is published for Offensity, making direct assessment of its profitability, growth rate, or ARR impossible for external parties. Risks include product-brand risk (Offensity could be de-prioritised or merged into a broader A1 Digital cybersecurity offering), intense competition from Tenable, Qualys, Rapid7, Detectify, Intruder, and Pentera, freemium positioning that may limit direct monetisation, and geographic concentration in DACH/Austria. Overall resilience is high due to parent strength, but standalone product viability is opaque.

Key strengths: Strong parent backing from Telekom Austria Group (~€5.36B revenue, investment-grade), Ultimate ownership by América Móvil provides deep financial resources, Recurring SaaS subscription revenue model with sticky customers, Cross-selling into A1's existing enterprise/SME customer base across CEE, Bundling within A1 Digital's broader cybersecurity portfolio, Group equity of ~€3.8B and growing EBIT trajectory

Risk factors: No standalone P&L disclosure for Offensity — profitability opaque, Product-brand risk: could be de-prioritised, rebranded or merged into broader A1 Digital offering, Highly competitive vulnerability-scanning market (Tenable, Qualys, Rapid7, Detectify, Intruder, Pentera), Freemium/low-price positioning limits direct revenue generation, Geographic concentration in DACH region, Austria-heavy customer base creates regional dependency

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report