Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Case Study: Running a Readiness Programme Without Buying Compliance Tooling

The client came to us having already priced a compliance automation subscription at five figures a year. They had assumed, reasonably, that a readiness programme requires one: something to hold the evidence, track the controls, and produce a readiness percentage for the board.

They did not buy it. The programme ran on our workspace instead, which we do not charge for, and that changed the shape of the budget before any control work started.

What the tooling was supposed to do

Stripped of the marketing, a compliance platform does four things. It holds a control set for the framework you are pursuing. It stores evidence against those controls. It tracks policies and who has acknowledged them. And it renders the whole thing as a percentage so somebody can report progress upward.

All four are genuinely useful. None of them is worth a recurring licence for a company running one readiness programme, which is what most first-time candidates are actually doing.

The trap is that the subscription is priced as infrastructure and used as a project tool. You buy it for the programme, the programme finishes, and the renewal arrives anyway. Companies then either pay for a tool nobody opens, or cancel and discover their evidence history lived inside it.

What automation actually automates

This is worth being precise about, because the category name oversells it.

The integrations are real. A platform connected to your cloud provider and your identity provider can genuinely pull configuration state on a schedule and flag when MFA is off for somebody or a bucket goes public. That is useful monitoring and it saves real time on a handful of technical controls.

What it does not do is the part that consumes the programme. It cannot decide whether the artefact you uploaded is the artefact an auditor will accept. It cannot tell you that your access review evidence is a screenshot when the auditor wanted the export with dates and the reviewer's name. It cannot chase the person who owns the vendor list, judge whether your system description matches what is actually in production, or negotiate sampling with the audit firm.

Roughly speaking, the automatable controls are a minority of any framework, and they are the ones companies are usually already doing. The controls that fail an audit tend to be organisational: reviews that never ran, owners who were never named, procedures that exist in someone's head. No integration fixes those.

So the honest description of a compliance platform is a well-organised filing system with monitoring attached to part of it. Priced accordingly, that is a fair product. Priced as the solution to readiness, it sets an expectation it cannot meet.

What the client used instead

The client ran the engagement in the traztech Workspace. It carries guided self-assessments across fourteen frameworks with every control explained in plain English, an evidence register, forty policy templates, a risk register, vendor questionnaires and audit-readiness scoring. There is no card, no trial clock and no paid tier, so nothing about the programme was gated behind an upgrade at the point it got serious.

Three things mattered more than the feature list.

It is the same register we work from. When we request an artefact, it lands against the control it evidences rather than in an email thread. When the auditor samples that control later, the artefact is already attached to it. A separate tool means somebody re-files everything at least once, and that usually happens during fieldwork when nobody has time.

The control explanations are in plain English. A large part of what a first-time candidate is paying for, in any tool, is a translation layer. The control text in the standard is written for assessors. Somebody on your side has to work out what it means for your company specifically, and if the tool does not do that, a person has to, and that person bills.

The client keeps it. When the engagement ends, the evidence, the policies and the assessment history stay in their workspace. That matters at the next cycle, because the expensive part of a second audit is reconstructing what you did during the first one.

Where the saving actually came from

The licence line is the obvious saving, and a five-figure annual commitment avoided is not nothing. It is still the smaller of the two. The larger saving was in not paying twice for the same work.

A compliance platform sold on automation still needs somebody to decide what evidence satisfies a control, to chase the people who own it, and to judge whether what came back is what an auditor will accept. That work does not disappear because the tool has an integration. Companies that buy the subscription frequently end up buying help as well, and the two overlap heavily: you are paying a vendor to hold the evidence and a consultant to tell you what to put in it.

Running both through one place meant the tool and the judgement were the same engagement. The client paid for the programme, not for the programme plus somewhere to keep it.

There is a second-order effect worth naming. When the register and the reviewer are the same system, the gap between "we uploaded something" and "that will pass" closes to zero. In a split setup, that gap is a review cycle, and review cycles are where timelines go.

Where a paid platform is the right answer

Worth being straight about this, because the answer is not always ours.

If you are maintaining several frameworks continuously, with a security team that lives in the tool daily, a genuine need for automated evidence collection across dozens of systems, and a compliance calendar that runs all year rather than in a burst, a commercial platform earns its money. Continuous control monitoring across a large estate is a real product category solving a real problem, and pretending otherwise would be silly.

The signals that you have crossed that line are reasonably clear. You have more than two frameworks live. Somebody's job title contains the word compliance. You are re-certifying on a rolling basis rather than preparing for a first audit. At that point the recurring cost buys recurring value.

For a company running its first or second readiness programme, the subscription is usually solving a problem the engagement already solves. That was the case here.

What to ask before you buy one

If you are being sold a platform during a readiness programme, four questions sort it out quickly.

What happens to my evidence if I cancel? Export format, and whether the assessment history comes with it.

Which controls does the automation actually cover? Ask for the list, not the percentage. Then check how many of those you were failing anyway.

Does this replace a person, or feed one? If the answer involves you still hiring help, price both together and compare that against a programme that includes the tooling.

Will my auditor accept evidence in this form? Ask the auditor, not the vendor.

The traztech Workspace is free to use whether or not you work with us. If you want to see what a control set looks like before committing to anything, that is the least expensive way to find out.

Note. The client is unnamed. Figures are described by what drives them rather than quoted, because audit pricing is specific to scope and we will not publish another firm's numbers.

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
15+
Penetration testing engagements delivered

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.