Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →traztech is a security and compliance firm for startups. We have founded and exited products, bootstrapped BrilliantHost, our own VPS hosting company, to $13K MRR, and published security research used to take down live botnets. We know what an early team can realistically afford to do, because we have been one.
traztech started as a group of operators: engineers, founders, and growth and ops leaders who got tired of watching good startups get bad advice. We've built and exited products, run the bootstrapped grind to profitability (we scaled BrilliantHost, our hosting company, to $13K MRR), and shipped infrastructure that serves millions of requests.
Security is where we go deepest. Five published CVEs, among them CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet, which CyberInsider covered. We also run SOC 2 Type II readiness and audit coordination, and co-deliver offensive testing with a specialist partner. Based in Canada, working with startups across North America and Europe.
Most of that work today takes the shape of fixed-scope SOC 2 and compliance engagements, stepping in as a fractional CISO, or standing up compliance programs for teams that don't yet have security leadership of their own.
We understand burn rates, runway pressure, and the need to move fast with limited resources. Every recommendation factors in where you are today.
We measure success by what shipped, what improved, and what unblocked your team. Pushing the fix beats writing a post-mortem about why it is still broken.
Evidence requests, auditor sampling and the chasing that comes with both land on us. Your engineers answer the questions only they can answer, and nothing else.
Speed matters, but so does quality. We help you find the sweet spot between moving quickly and building something that will not collapse at the worst possible time.
Web, network, cloud and API testing, scoped so the report doubles as audit evidence. Led by a published CVE researcher.
SOC 2, ISO 27001, HIPAA, PCI DSS, CPCSC and the Canadian privacy stack. Readiness and audit prep, with an independent auditor.
A named security owner for buyer questionnaires, board reporting and the compliance roadmap, without a full-time hire.
Prompt injection, data leakage, agent abuse and model supply chain, for teams shipping AI features into production.
A responder on a contracted SLA, plus tabletop exercises that test the plan before the plan matters.
AWS, Azure and GCP posture: identity, exposure, data protection and the misconfigurations that cause breaches.
Every figure traces to published work: the zero-exception Type II, the revised audit quote, the CVEs, and the 75-day track.
Whether it is a first SOC 2, a second framework running alongside it, or a penetration test somebody has asked you for, the first conversation is free and we will tell you if you do not need us yet.
Book a Free ConsultationTrack record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.