Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
traztech Workspace · free forever

Work out what compliance
actually asks of you.

A free compliance workspace. Pick a framework, walk every control with a plain-English explanation of what it means and what evidence an auditor will want, attach that evidence as you collect it, and watch a readiness score you can defend. 10 frameworks, 783 requirements, no credit card and nothing locked.

Start your free assessment Talk to someone first

Passwordless sign-in. No card. No trial clock. Built and run by TrazTech, a Toronto security and compliance firm.

Eight things instead of a spreadsheet

Most compliance work still runs on a tracker someone built in a hurry, a folder of screenshots, and a calendar reminder that nobody owns. This replaces all of that with one workspace.

It is free, and here is how we make money

We would rather say this plainly than let you wonder where the catch is.

What is free

All of it. Every framework and control, the evidence register, policy library, risk register, vendor questionnaires, calendar, scoring and read-only auditor access. No paid tier, no seat limit, no export fee, no padlocks. Use it for two years without ever speaking to us and it stays free.

Where the money is

We are a security and compliance consultancy. The Workspace finds the gaps, and some are genuinely hard to close: policies, the risk assessment, evidence, a pentest, managing the auditor. Teams that want help with that hire us. A free tool showing the real scope of the problem is the most honest advertisement we can run.

What that means for you

Recommendations only appear against a control you marked as not met or partially met. Tell the Workspace your pentest is current and it will not try to sell you one. Cross-selling against work you have already done would make every other recommendation worthless.

The same work, without the line item

A compliance platform is a control library, an evidence store, a policy tracker and a percentage for the board. You need all four to get through a readiness programme. The question is whether that should be a recurring subscription.

traztech Workspace Typical GRC platform
The bill
Licence cost$0, and there is no paid tier$7,500 to $50,000 a year, depending on scope and framework count
CommitmentNone. No card, no renewal dateAnnual contract, commonly 12 to 36 months
Cost if you hire us$0. You were going to need a workspace either wayUnchanged. The subscription sits on top of the consulting fee
Effect on your audit quoteA documented readiness position took $11,000 off a five-figure quote on one engagementNone. The audit firm prices your readiness, not your tooling
What you get
Control libraries, 10 frameworks Included Included
Evidence register mapped to controls Included Included
40 policy templates with approval history Included Included
Risk register Included Included
Vendor risk questionnaires Included Included
Compliance calendar Included Included
Audit-readiness scoring Included Included
Read-only auditor access Included Included
Every control written in plain English IncludedVaries. Often the clause text with a help article beside it
Scheduled checks against your cloud and identity systemsYes. Daily, filed as evidence against the control Included
Breadth of pre-built integrationsSeven built in, plus any HTTP API you describeHundreds, including endpoints and HR
A firm that closes the gaps it findsYes. Policies, risk assessment, pentest, auditor managementNo. Findings go to your team or your support queue
Your evidence when it endsStays in your workspaceExport it before the contract lapses
Year one tooling cost$0$7,500 to $50,000 a year

The band is what compliance automation platforms are publicly reported to charge across startup and mid-market scopes. None of them publish a price, so treat it as a range rather than a quote. We are not naming anyone, and the honest comparison of what they do better is further down this page.

The $11,000 came off the audit firm's own number once the client's readiness position was documented: how that worked. A separate client had a five-figure subscription approved, ran the programme here instead and paid no licence fee: what that saved.

10 frameworks, 783 requirements

Counts below are the full control libraries, pulled live from the platform. Scoping questions will usually reduce what you have to answer. Pick one to start a workspace against it.

You can run more than one framework in the same workspace. Where controls overlap, and SOC 2 and ISO 27001 overlap a great deal, evidence you attach once counts for both.

How this compares to Vanta and Drata

Vanta and Drata are good products and thousands of companies get certified with them. They are not what this is, and pretending otherwise would waste your time.

What they do well

Breadth. Hundreds of pre-built integrations covering endpoints, HR systems and tools this does not reach, maintained by teams who do only that. If your control set spans a large estate, that coverage is worth paying for. They also have deep auditor networks and years of integration work behind them.

What this does not do

It connects to fewer systems. Seven are built in, and anything else with an API has to be described as a check rather than picked from a list. There is no endpoint agent and no HR integration. If you need a control watched on every laptop, or evidence pulled from your HRIS, buy one of them. We work alongside them and will say so when that is the right call.

Short version: if your estate is large enough to need hundreds of integrations, endpoint agents and HR coverage, buy a platform. If you need to understand what a framework requires, work through it honestly, have the systems you do run checked daily, and have someone who can close the hard gaps, start here. Plenty of teams end up doing both.

Run it under your own brand

If you already advise clients on security or IT, compliance is the question you keep getting asked and the one you have no tooling for. There is a white-label partner tier for that.

See the partner programme

Read-only access, so fieldwork stops being a scavenger hunt

Your client can invite you into their workspace with an auditor role. It is genuinely read-only: every mutating control is hidden, not just disabled.

  • Read every assessment answer, with the client's own notes on how the control is implemented
  • Open the evidence attached to each control, with upload dates and owners
  • See policies with their version and approval history
  • Review the risk register and the vendor assessments
  • Change nothing, so there is no question about whether the record moved during fieldwork

It costs the auditor nothing and it does not require the client to be a TrazTech customer. If you are an audit firm and want a walkthrough before you suggest it to a client, book a call.

What the first hour looks like

01

Create a workspace

Email address and a company name. We email you a one-time sign-in link, so there is no password to invent. No card at any point.

02

Pick a framework and answer the scoping questions

Five or six questions that decide which controls actually apply to you. This is where a 155-requirement framework often becomes a much shorter list.

03

Walk the controls

Met, partially met, not met, or not applicable, with a note on how. Most teams get a first honest pass done in two or three sittings. You will not finish in an afternoon, and anyone who tells you otherwise is selling something.

04

Look at the gaps

You get a readiness score, a ranked gap list with effort estimates, and a starting policy set. From there you either work through it yourself, which is fine, or you ask us for help with the parts you would rather not do.

Find out what you are actually missing

Free workspace, 10 frameworks, 783 requirements explained in plain English. If you would rather talk it through with a human before you start, that is free too.

Start your free assessment Book a free readiness call

Already have a workspace? Sign in.

Frequently asked questions

Is traztech Workspace really free?

Yes. No credit card, no trial countdown, no locked features. Everything is open from the moment you create a workspace. We make money when a team wants help closing the gaps the platform finds. The platform itself is not the product we sell.

How is it different from Vanta or Drata?

It is free with no annual contract, every control is written out in plain English rather than assuming you know it, and there is a firm behind it that can do the remediation, not only report on it. It connects to AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira, and to any other system with an API you can describe a check against. Those checks run daily and file evidence against the control they prove. What Vanta and Drata have that this does not is breadth: hundreds of pre-built integrations, endpoint and HR coverage, and years of work behind them. If you need that breadth, buy one of them.

Which frameworks are covered?

Currently 10: SOC 2, ISO 27001, ISO 42001, NIST CSF 2.0, HIPAA, PCI DSS v4.0.1, GDPR, PIPEDA, Quebec Law 25, EU AI Act. That is 783 individual controls, criteria, and obligations, each written out in plain English.

What happens to my data?

Your workspace is yours. Assessments, evidence, policies, and risks are scoped to your organisation and are not shared with anyone else. Sign-in is passwordless with short-lived one-time links, so there is no password to leak. You can export your work and you can ask us to delete the workspace.

Can our auditor use it?

Yes. You can invite an auditor to your workspace with a read-only role. They can read every assessment answer, open the evidence attached to each control, and see your policies and their approval history, and they cannot change anything. It is meant to replace the shared drive of screenshots that most audits still run on.

We are an MSP. Can we use this with our own clients?

Yes. There is a white-label partner tier where you run client workspaces under your own brand, with your logo and domain, and keep the client relationship. Details are on the partners page.

Does a self-assessment make us compliant?

No, and no tool can. A self-assessment tells you where you stand against a framework and what evidence you still owe. Certification or attestation comes from an independent auditor or certification body reviewing your actual controls and evidence. The platform is built to get you to that review with far less pain, not to replace it.

What this replaces. A client who had already priced a compliance automation subscription ran their whole programme here instead: running readiness without buying compliance tooling.