Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A customer, an investor, or a renewal wants proof your security holds up. We get you audit-ready: SOC 2, ISO 27001, penetration testing, and security leadership.
Readiness and audit prep, run end to end. We are the prep expert, not the auditor: an independent CPA firm signs the report, we do everything before it.
Web app, network, cloud, and server hardening tests, vulnerability scanning, and a TRA document when procurement asks for one.
Senior security leadership on your security questionnaires, SOC 2 evidence, and board deck. Without the $300K comp line.
Prompt injection, RAG leakage, and agent abuse testing across the OWASP LLM Top 10. Delivered with our offensive-security partner.
A named team, a contracted SLA, and someone who actually answers the phone at 2 AM, for a fraction of building an internal SOC.
Level 1 self-assessment and Level 2 readiness for Canadian defence suppliers. No certification, no bid.
PHI safeguards, risk analysis, and the policies US healthcare buyers and payers expect. Run alongside SOC 2 so you build the evidence once.
Scope reduction first, then the readiness and testing your acquirer or enterprise customer requires. We minimize what you have to secure.
We work with SaaS, fintech, healthcare, AI, and more, from startups to enterprise. See who we help →
Adverse opinions are real, and ISO 27001 withholds certificates at Stage 2. The commoner outcome is worse: the auditor pauses mid-fieldwork. You paid for an audit, there is no report, and doing it again means paying again.
Your team really does the quarterly access review. There is no dated record of it, so for a Type II there is nothing to sample.
Fourteen characters on paper, eight in the identity provider. Auditors test against what your policy says, so every gap is an exception.
A Type II covers the whole observation window. Two weeks of evidence in a six-month period is the most expensive misunderstanding in compliance.
A platform confirms your cloud config. It cannot confirm the access review ran, the IR plan was tested, or the change policy matches how you deploy.
Readiness is the cost you defer, then pay at a worse moment. We make sure your auditor never has to pause. What a stall costs →
Every figure traces to published work: the zero-exception Type II, the revised audit quote, the CVEs, and the 75-day track.
traztech is led by Jacob Masse, a published security researcher who both finds the attacks and ships the compliance. You work with him directly, not an account manager or a handoff to juniors.
See the researchIncluding CVE-2024-45163 (CVSS 9.1), the flaw in the Mirai botnet that let defenders shut down active command-and-control servers.
Stood up a full program across 76 controls and coordinated the external pentest through to attestation.
Founded AttackEngine, an anti-DDoS platform acquired within a year of launch.
Across pentesting, infrastructure hardening, and compliance for startups in North America.
Built in-house by Jacob as Head of Operations: 76 controls, a five-layer change-approval flow and a 60-plus asset audit, across a team of 15. Passed with zero exceptions while the platform held 99.9% uptime.
A Waterloo data centre operator, around 20 people. Type II across Security, Availability and Confidentiality alongside ISO 27001:2022, run together rather than in sequence. Findings delivered and remediated.
A VC-backed Ontario medtech company putting clinical AI in front of practitioners. SOC 2 covering the product and the clinical data handling that enterprise health buyers ask to see before signing.
“He exhibits natural leadership, professionalism, and technical skill. His ability to tackle problems...is truly impressive.”
“He keeps things moving and handles both the technical and operational sides without overcomplicating things.”
“One of the most competent individuals I have worked with. His technical skills and management styles are extremely efficient.”
“Has saved us from potential data breaches on multiple occasions with his cyber security oriented background. We have been able to rely on Jacob for emergency pushes.”
No long discovery phase and no 80-page strategy document. We scope the boundary, tell you what the work is, and give you the price before you commit. Then the programme itself runs in four phases, and the boundary decision in phase one is the one that carries the rest.
30 minutes. We learn your stack, team, and biggest pain point. You learn if we are the right fit.
Within 48 hours you get a clear proposal: what we will do, how long it takes, and what it costs. No surprises.
We close the gaps and build the evidence, working from the request list your auditor will issue. You retrieve what only you can, and we tell you what will and will not pass.
Sampling requests come to us, not your engineers. We hold the auditor relationship through fieldwork so nothing stops mid-examination. The four phases in full.
Not email threads and shared spreadsheets. Track findings by severity, respond to evidence requests, e-sign documents, and watch milestones close in real time. For small and mid-size readiness work, it replaces the client-facing side of Vanta or Drata, without the platform price tag.
Every finding ranked by severity, with recommended remediation and a target date. Watch your open-critical count fall to zero.
A live checklist of what we need for the audit. Upload directly against each item, see what is still outstanding at a glance.
Proposals, agreements, and deliverables in one place, versioned and downloadable. No more hunting through your inbox.
A live timeline of the engagement so you always know what is done, what is in progress, and what is next.
Review and sign agreements and policies right in the portal, with a legally binding electronic signature. No third-party tool.
See what is due, pay by card or bank transfer, and pull your full payment history whenever finance asks.
To be precise: this is an engagement and evidence portal, where your project with us lives. It is not an automated, continuous control-monitoring scanner.
Book a free 30-minute readiness call. We will look at what your buyer is asking for and tell you what the work involves.
Book a free 30-minute readiness call