Common Sense Security
SealSec is a Dutch security consultancy for SaaS teams: penetration testing, cloud and API security assessments, and hands-on remediation support. Practical security reviews that strengthen what matters.
How a security sprint works
Inventory, test, triage, verify: how SealSec runs security testing as a loop that ends in a retest, not a PDF that gathers dust.
Read this Jul 30, 2026Explore everything
11 pieces across 4 places
Fresh off the press
CVE-2024-6387: regreSSHion, when a patched bug comes back
regreSSHion (CVE-2024-6387) is an OpenSSH RCE that returned years after being fixed. Why regressions are a security event, and how to catch them.
Jul 30, 2026 AdvisoriesCVE-2021-44228: Log4Shell, still worth understanding
Log4Shell (CVE-2021-44228) was a CVSS 10.0 RCE in Apache Log4j 2. What it was, who it hit, and the dependency-security lesson that still applies.
Jul 30, 2026 WikiCoordinated vulnerability disclosure
How coordinated vulnerability disclosure works, what a CVD policy contains, and why publishing one is the cheapest trust signal a SaaS company can ship.
Jul 30, 2026 BlogHow to answer enterprise security questionnaires
Security questionnaires eat weeks. Build one answer library on CAIQ/CCM controls, attach the right evidence, and answer once instead of every time.
Jul 30, 2026 BlogHow to prepare your SaaS for its first pentest
What to scope, which test accounts to prepare and what a useful report looks like: a practical guide to getting real value from your first penetration test.
Jul 30, 2026 WikiTenant isolation
Tenant isolation keeps one SaaS customer's data away from another. Silo vs. pool models, why buyers ask about it, and how a pentest actually tests it.
Jul 30, 2026Not sure how your SaaS would hold up against a real attacker?
SealSec runs practical security sprints for SaaS teams: web, API, cloud and AI product security, with clear findings and remediation support.
Plan a free discovery callGratis verkenningsgesprek | SealSec B.V. | info@sealsec.nl