Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
traztechsecurity & compliance for startups est. 2021
01  ·  what we do

Security that holds up.
Compliance that
passes SOC 2.

A customer, an investor, or a renewal wants proof your security holds up. We get you audit-ready: SOC 2, ISO 27001, penetration testing, and security leadership.

6published CVEs SOC 2ISO 27001PCI DSS v.26.08
AWS
Kubernetes
Terraform
GitHub Actions
Datadog
SOC 2
ISO 27001
PagerDuty
Docker
Cloudflare
Vanta
Linear
AWS
Kubernetes
Terraform
GitHub Actions
Datadog
SOC 2
ISO 27001
PagerDuty
Docker
Cloudflare
Vanta
Linear

Security and compliance,
built for startup speed.

We work with SaaS, fintech, healthcare, AI, and more, from startups to enterprise. See who we help →

24/7
Support availability
8x
Avg. ops efficiency
60%
Manual work reduced
98%
Client retention

You get the person
doing the work.

traztech is led by Jacob Masse, a published security researcher who both finds the attacks and ships the compliance. You work with him directly, not an account manager or a handoff to juniors.

See the research

6 published CVEs

Including CVE-2024-45163 (CVSS 9.1), the flaw in the Mirai botnet that let defenders shut down active command-and-control servers.

SOC 2 Type II, from scratch

Stood up a full program across 76 controls and coordinated the external pentest through to attestation.

Built and exited

Founded AttackEngine, an anti-DDoS platform acquired within a year of launch.

20+ engagements

Across pentesting, infrastructure hardening, and compliance for startups in North America.

We don't just consult. We deliver.

Security · SOC 2

Zero to SOC 2 Type II at Humera

Built in-house by Jacob as Head of Operations: 76 controls, a five-layer change-approval flow and a 60-plus asset audit, across a team of 15. Passed with zero exceptions while the platform held 99.9% uptime.

76Controls
ZeroExceptions
Read the case study
Compliance · SOC 2 + ISO 27001

SOC 2 and ISO 27001 in parallel

A Waterloo data centre operator, around 20 people. Type II across Security, Availability and Confidentiality alongside ISO 27001:2022, run together rather than in sequence. Findings delivered and remediated.

2Frameworks
Phase 1Delivered
Read the case study
Compliance · Medtech

SOC 2 for an AI clinical assistant

A VC-backed Ontario medtech company putting clinical AI in front of practitioners. SOC 2 covering the product and the clinical data handling that enterprise health buyers ask to see before signing.

84Evidence items scoped
Type IClinical AI in scope
Read the case study

What a programme actually costs you, and what it saves

The people who worked with us.

“He exhibits natural leadership, professionalism, and technical skill. His ability to tackle problems...is truly impressive.”

Gavin McIntosh
Formerly Lead Data Scientist, Humera · now at Webflow

“He keeps things moving and handles both the technical and operational sides without overcomplicating things.”

Matthew Ransley
CTO, Humera

“One of the most competent individuals I have worked with. His technical skills and management styles are extremely efficient.”

Luka Stankovic
Executive Consultant

“Proficient in PHP, MySQL, CloudOps, and DevOps Pipelines. He has helped us out many times and always comes through.”

Ryan Wilke
CEO & Founder, Lorikeet Security

From first call to a scoped engagement in under two weeks.

No long discovery phase and no 80-page strategy document. We scope the boundary, tell you what the work is, and give you the price before you commit.

01

Discovery call

30 minutes. We learn your stack, team, and biggest pain point. You learn if we are the right fit.

02

Scope & proposal

Within 48 hours you get a clear proposal: what we will do, how long it takes, and what it costs. No surprises.

03

Embed & execute

We join your Slack, your standups, your repo. We ship real work from week one. You see progress daily.

04

Measure & iterate

Monthly reviews with clear metrics. We adjust scope as your needs change. No lock-in contracts.

Every engagement runs
in your portal.

Not email threads and shared spreadsheets. Track findings by severity, respond to evidence requests, e-sign documents, and watch milestones close in real time. For small and mid-size readiness work, it replaces the client-facing side of Vanta or Drata, without the platform price tag.

Findings & remediation

Every finding ranked by severity, with recommended remediation and a target date. Watch your open-critical count fall to zero.

Evidence requests

A live checklist of what we need for the audit. Upload directly against each item, see what is still outstanding at a glance.

Documents

Proposals, agreements, and deliverables in one place, versioned and downloadable. No more hunting through your inbox.

Milestones

A live timeline of the engagement so you always know what is done, what is in progress, and what is next.

E-signature

Review and sign agreements and policies right in the portal, with a legally binding electronic signature. No third-party tool.

Invoices

See what is due, pay by card or bank transfer, and pull your full payment history whenever finance asks.

To be precise: this is an engagement and evidence portal, where your project with us lives. It is not an automated, continuous control-monitoring scanner.

Find out where you
actually stand.

Book a free 30-minute readiness call. We will look at what your buyer is asking for and tell you what the work involves.

Book a free 30-minute readiness call
Book a Call