Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
traztechsecurity & compliance for startups est. 2021
01  ·  what we do

Security that holds up.
Compliance that
passes SOC 2.

A customer, an investor, or a renewal wants proof your security holds up. We get you audit-ready: SOC 2, ISO 27001, penetration testing, and security leadership.

5published CVEs SOC 2ISO 27001PCI DSS v.26.08
SOC 2
ISO 27001
HIPAA
PCI DSS
CPCSC
ISO 42001
GDPR
PIPEDA
Quebec Law 25
NIST CSF
Vanta
Drata
AWS
Azure
GCP
Cloudflare
SOC 2
ISO 27001
HIPAA
PCI DSS
CPCSC
ISO 42001
GDPR
PIPEDA
Quebec Law 25
NIST CSF
Vanta
Drata
AWS
Azure
GCP
Cloudflare

Security and compliance,
built for startup speed.

We work with SaaS, fintech, healthcare, AI, and more, from startups to enterprise. See who we help →

Audits do fail.
Stalling costs more.

Adverse opinions are real, and ISO 27001 withholds certificates at Stage 2. The commoner outcome is worse: the auditor pauses mid-fieldwork. You paid for an audit, there is no report, and doing it again means paying again.

The control runs, in someone's head

Your team really does the quarterly access review. There is no dated record of it, so for a Type II there is nothing to sample.

The policy promises more than the system does

Fourteen characters on paper, eight in the identity provider. Auditors test against what your policy says, so every gap is an exception.

MFA turned on two weeks before fieldwork

A Type II covers the whole observation window. Two weeks of evidence in a six-month period is the most expensive misunderstanding in compliance.

The dashboard is green anyway

A platform confirms your cloud config. It cannot confirm the access review ran, the IR plan was tested, or the change policy matches how you deploy.

Readiness is the cost you defer, then pay at a worse moment. We make sure your auditor never has to pause. What a stall costs →

Zero
Exceptions on a SOC 2 Type II
$11K
Off an audit quote, for arriving ready
5
Published CVEs
75
Days to audit-ready

Every figure traces to published work: the zero-exception Type II, the revised audit quote, the CVEs, and the 75-day track.

You get the person
doing the work.

traztech is led by Jacob Masse, a published security researcher who both finds the attacks and ships the compliance. You work with him directly, not an account manager or a handoff to juniors.

See the research

5 published CVEs

Including CVE-2024-45163 (CVSS 9.1), the flaw in the Mirai botnet that let defenders shut down active command-and-control servers.

SOC 2 Type II, from scratch

Stood up a full program across 76 controls and coordinated the external pentest through to attestation.

Built and exited

Founded AttackEngine, an anti-DDoS platform acquired within a year of launch.

20+ engagements

Across pentesting, infrastructure hardening, and compliance for startups in North America.

We don't just consult. We deliver.

Security · SOC 2

Zero to SOC 2 Type II at Humera

Built in-house by Jacob as Head of Operations: 76 controls, a five-layer change-approval flow and a 60-plus asset audit, across a team of 15. Passed with zero exceptions while the platform held 99.9% uptime.

76Controls
ZeroExceptions
Read the case study
Compliance · SOC 2 + ISO 27001

SOC 2 and ISO 27001 in parallel

A Waterloo data centre operator, around 20 people. Type II across Security, Availability and Confidentiality alongside ISO 27001:2022, run together rather than in sequence. Findings delivered and remediated.

2Frameworks
Phase 1Delivered
Read the case study
Compliance · Medtech

SOC 2 for an AI clinical assistant

A VC-backed Ontario medtech company putting clinical AI in front of practitioners. SOC 2 covering the product and the clinical data handling that enterprise health buyers ask to see before signing.

84Evidence items scoped
Type IClinical AI in scope
Read the case study

What a programme actually costs you, and what it saves

The people who worked with us.

“He exhibits natural leadership, professionalism, and technical skill. His ability to tackle problems...is truly impressive.”

Gavin McIntosh
Formerly Lead Data Scientist, Humera · now at Webflow

“He keeps things moving and handles both the technical and operational sides without overcomplicating things.”

Matthew Ransley
CTO, Humera

“One of the most competent individuals I have worked with. His technical skills and management styles are extremely efficient.”

Luka Stankovic
Executive Consultant

“Has saved us from potential data breaches on multiple occasions with his cyber security oriented background. We have been able to rely on Jacob for emergency pushes.”

Ryan Wilke
CEO & Founder, Lorikeet Security

From first call to a scoped engagement in under two weeks.

No long discovery phase and no 80-page strategy document. We scope the boundary, tell you what the work is, and give you the price before you commit. Then the programme itself runs in four phases, and the boundary decision in phase one is the one that carries the rest.

01

Discovery call

30 minutes. We learn your stack, team, and biggest pain point. You learn if we are the right fit.

02

Scope & proposal

Within 48 hours you get a clear proposal: what we will do, how long it takes, and what it costs. No surprises.

03

Remediate & evidence

We close the gaps and build the evidence, working from the request list your auditor will issue. You retrieve what only you can, and we tell you what will and will not pass.

04

Hand off to the auditor

Sampling requests come to us, not your engineers. We hold the auditor relationship through fieldwork so nothing stops mid-examination. The four phases in full.

Every engagement runs
in your portal.

Not email threads and shared spreadsheets. Track findings by severity, respond to evidence requests, e-sign documents, and watch milestones close in real time. For small and mid-size readiness work, it replaces the client-facing side of Vanta or Drata, without the platform price tag.

Findings & remediation

Every finding ranked by severity, with recommended remediation and a target date. Watch your open-critical count fall to zero.

Evidence requests

A live checklist of what we need for the audit. Upload directly against each item, see what is still outstanding at a glance.

Documents

Proposals, agreements, and deliverables in one place, versioned and downloadable. No more hunting through your inbox.

Milestones

A live timeline of the engagement so you always know what is done, what is in progress, and what is next.

E-signature

Review and sign agreements and policies right in the portal, with a legally binding electronic signature. No third-party tool.

Invoices

See what is due, pay by card or bank transfer, and pull your full payment history whenever finance asks.

To be precise: this is an engagement and evidence portal, where your project with us lives. It is not an automated, continuous control-monitoring scanner.

Find out where you
actually stand.

Book a free 30-minute readiness call. We will look at what your buyer is asking for and tell you what the work involves.

Book a free 30-minute readiness call
Book a Call