Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Canada

Built by operators,
backed by real research.

traztech is a security and compliance firm for startups. We have founded and exited products, bootstrapped BrilliantHost, our own VPS hosting company, to $13K MRR, and published security research used to take down live botnets. We know what an early team can realistically afford to do, because we have been one.

One team. The whole startup stack.

traztech started as a group of operators: engineers, founders, and growth and ops leaders who got tired of watching good startups get bad advice. We've built and exited products, run the bootstrapped grind to profitability (we scaled BrilliantHost, our hosting company, to $13K MRR), and shipped infrastructure that serves millions of requests.

Security is where we go deepest. Five published CVEs, among them CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet, which CyberInsider covered. We also run SOC 2 Type II readiness and audit coordination, and co-deliver offensive testing with a specialist partner. Based in Canada, working with startups across North America and Europe.

Most of that work today takes the shape of fixed-scope SOC 2 and compliance engagements, stepping in as a fractional CISO, or standing up compliance programs for teams that don't yet have security leadership of their own.

SOC 2 & Compliance Fractional CISO Penetration Testing AI / LLM Security Incident Response Cloud Cost Review Auditor Management ISO 27001

Four principles. Zero slide decks.

01

Startup-first

We understand burn rates, runway pressure, and the need to move fast with limited resources. Every recommendation factors in where you are today.

02

Results over reports

We measure success by what shipped, what improved, and what unblocked your team. Pushing the fix beats writing a post-mortem about why it is still broken.

03

We absorb the work, not delegate it

Evidence requests, auditor sampling and the chasing that comes with both land on us. Your engineers answer the questions only they can answer, and nothing else.

04

Ship fast, ship right

Speed matters, but so does quality. We help you find the sweet spot between moving quickly and building something that will not collapse at the worst possible time.

Five things, done properly.

Penetration Testing

Web, network, cloud and API testing, scoped so the report doubles as audit evidence. Led by a published CVE researcher.

Compliance

SOC 2, ISO 27001, HIPAA, PCI DSS, CPCSC and the Canadian privacy stack. Readiness and audit prep, with an independent auditor.

Fractional CISO

A named security owner for buyer questionnaires, board reporting and the compliance roadmap, without a full-time hire.

AI / LLM Security

Prompt injection, data leakage, agent abuse and model supply chain, for teams shipping AI features into production.

Incident Response

A responder on a contracted SLA, plus tabletop exercises that test the plan before the plan matters.

Cloud Security

AWS, Azure and GCP posture: identity, exposure, data protection and the misconfigurations that cause breaches.

We track outcomes, not hours.

Zero
Exceptions on a SOC 2 Type II
$11K
Off an audit quote, for arriving ready
5
Published CVEs
75
Days to audit-ready

Every figure traces to published work: the zero-exception Type II, the revised audit quote, the CVEs, and the 75-day track.

Let’s get you
through the audit.

Whether it is a first SOC 2, a second framework running alongside it, or a penetration test somebody has asked you for, the first conversation is free and we will tell you if you do not need us yet.

Book a Free Consultation

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.