Skip to content
pcipentest

A sourced reference on PCI DSS testing: what is confirmed, what is behind a licence gate, and who actually decides what you validate.

Run the scope finder→
  • 01What we can prove
  • 02Scan or test
  • 03Scope finder
  • 04Who validates
  • 05PCI, DORA, NIS2
  • 06Guides
Home

Privacy policy

Updated 13 September 2026

Operator and scope

pcipentest.com is a free reference operated by SEQ SIA (OffSeq), registration number 40203410806, Lastādijas iela 12 k-3, Riga, LV-1050, Latvia. The site has no user accounts, no newsletter, no contact form and no comments.

The testing scope finder

The scope finder runs entirely in your browser. The role, volume band, segmentation answer, environment and data types you select are held in page memory for as long as the page is open. They are not sent to OffSeq, not written to local storage or any cookie, not included in analytics events, and not added to outbound links. Closing or reloading the page discards them. The finder is educational: it does not inspect your network, your systems or your evidence, and its output is a reference rather than an assessment.

Technical requests and traffic measurement

Serving a page through Cloudflare involves technical request data, including an IP address, browser headers, the requested URL and the request time. These data support delivery, security and operation of the site. Cloudflare may set its own security cookies; those are separate from the site application.

The site sends page views and clicks on OffSeq service and contact links to our self-hosted Plausible service at in.ainalytic.net. Events include the site domain, the public page address, limited campaign parameters and the referring site's origin when available. A link-click event adds only the destination path and a static placement label such as header, hero or scope-finder. Scope finder answers and results are never sent. The application does not set analytics cookies or a persistent visitor identifier; the collector receives technical network information with the request. Cookieless measurement is still data processing.

Measurement is disabled when the browser signals Do Not Track or Global Privacy Control, when the local-storage preference plausible_ignore is set to true, and for previews, local development and recognized automation. OffSeq links may carry static referral labels identifying this resource and the link placement; those labels never contain your answers.

Purpose, legal basis and retention

We use technical request data to operate and secure the site, and page-view and link-click statistics to understand how the resource is used and how much interest there is in OffSeq services. The operator's stated legal basis for these purposes is legitimate interests under Article 6(1)(f) GDPR. Hosting and infrastructure providers process requests on our behalf; the analytics service is self-hosted. Data are kept only as long as needed for those purposes and any applicable legal obligation. The operator's privacy policy explains its retention criteria, providers and transfer safeguards.

Contact and external links

If you email support@offseq.com, we receive the address, the message and anything you choose to include, so that we can reply. Correspondence is retained while it is needed to handle the enquiry or the business relationship. OffSeq service links, the card brand programme pages and the sources cited in the guides take you to sites with their own privacy notices.

Your rights

Subject to the conditions in the GDPR you may request access, correction, deletion, restriction or portability, and object to processing. Contact support@offseq.com. You may also complain to Latvia's Data State Inspectorate or to the supervisory authority where you live or work. The cookie and browser-storage notice covers what is and is not stored in your browser.

pcipentest

pcipentest.com is a free reference on testing under the PCI Data Security Standard: which tests the standard and the card brands actually ask for, how an ASV scan differs from a penetration test, when segmentation testing applies, and which of those statements can be sourced to a document anyone can open.

••••••••••••4242

Guides

  • ASV scan or pentest?
  • Segmentation testing
  • Levels and validation
  • PCI, DORA and NIS2

Professional help

  • Penetration testing and security audits
  • Compliance readiness
  • Define a testing scope
  • Talk to OffSeq

Information

  • About
  • Privacy policy
  • Cookies and browser storage

pcipentest.com is a free reference maintained by the OffSeq security team. OffSeq is not a Qualified Security Assessor company and not an Approved Scanning Vendor. It cannot sign a Report on Compliance, an Attestation of Compliance or an ASV scan report.

PCI DSS, PCI, SAQ, ROC, AOC, QSA and ASV are terms of the PCI Security Standards Council, LLC. Visa, Mastercard, American Express, Discover and JCB are trademarks of their respective owners. This site is independent and is not affiliated with, endorsed by or accredited by any of them.

Operated by SEQ SIA · Riga, Latvia