Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A free compliance workspace. Pick a framework, walk every control with a plain-English explanation of what it means and what evidence an auditor will want, attach that evidence as you collect it, and watch a readiness score you can defend. 10 frameworks, 783 requirements, no credit card and nothing locked.
Passwordless sign-in. No card. No trial clock. Built and run by TrazTech, a Toronto security and compliance firm.
Most compliance work still runs on a tracker someone built in a hurry, a folder of screenshots, and a calendar reminder that nobody owns. This replaces all of that with one workspace.
We would rather say this plainly than let you wonder where the catch is.
All of it. Every framework and control, the evidence register, policy library, risk register, vendor questionnaires, calendar, scoring and read-only auditor access. No paid tier, no seat limit, no export fee, no padlocks. Use it for two years without ever speaking to us and it stays free.
We are a security and compliance consultancy. The Workspace finds the gaps, and some are genuinely hard to close: policies, the risk assessment, evidence, a pentest, managing the auditor. Teams that want help with that hire us. A free tool showing the real scope of the problem is the most honest advertisement we can run.
Recommendations only appear against a control you marked as not met or partially met. Tell the Workspace your pentest is current and it will not try to sell you one. Cross-selling against work you have already done would make every other recommendation worthless.
A compliance platform is a control library, an evidence store, a policy tracker and a percentage for the board. You need all four to get through a readiness programme. The question is whether that should be a recurring subscription.
| traztech Workspace | Typical GRC platform | |
|---|---|---|
| The bill | ||
| Licence cost | $0, and there is no paid tier | $7,500 to $50,000 a year, depending on scope and framework count |
| Commitment | None. No card, no renewal date | Annual contract, commonly 12 to 36 months |
| Cost if you hire us | $0. You were going to need a workspace either way | Unchanged. The subscription sits on top of the consulting fee |
| Effect on your audit quote | A documented readiness position took $11,000 off a five-figure quote on one engagement | None. The audit firm prices your readiness, not your tooling |
| What you get | ||
| Control libraries, 10 frameworks | Included | Included |
| Evidence register mapped to controls | Included | Included |
| 40 policy templates with approval history | Included | Included |
| Risk register | Included | Included |
| Vendor risk questionnaires | Included | Included |
| Compliance calendar | Included | Included |
| Audit-readiness scoring | Included | Included |
| Read-only auditor access | Included | Included |
| Every control written in plain English | Included | Varies. Often the clause text with a help article beside it |
| Scheduled checks against your cloud and identity systems | Yes. Daily, filed as evidence against the control | Included |
| Breadth of pre-built integrations | Seven built in, plus any HTTP API you describe | Hundreds, including endpoints and HR |
| A firm that closes the gaps it finds | Yes. Policies, risk assessment, pentest, auditor management | No. Findings go to your team or your support queue |
| Your evidence when it ends | Stays in your workspace | Export it before the contract lapses |
| Year one tooling cost | $0 | $7,500 to $50,000 a year |
The band is what compliance automation platforms are publicly reported to charge across startup and mid-market scopes. None of them publish a price, so treat it as a range rather than a quote. We are not naming anyone, and the honest comparison of what they do better is further down this page.
The $11,000 came off the audit firm's own number once the client's readiness position was documented: how that worked. A separate client had a five-figure subscription approved, ran the programme here instead and paid no licence fee: what that saved.
Counts below are the full control libraries, pulled live from the platform. Scoping questions will usually reduce what you have to answer. Pick one to start a workspace against it.
The attestation report North American enterprise buyers ask for before they sign. Built on the Trust Services Criteria.
93 controls + 25 clausesThe international certification for an information security management system. Preferred by EU, UK, and APAC buyers.
38 controls + 29 clausesThe AI management system standard. The emerging answer when a buyer asks how you govern the AI in your product.
106 subcategoriesA voluntary framework organised into six functions, assessed as a current profile against a target profile. Not certifiable, but widely used as a common language with boards and insurers.
84 requirementsUS health data law. No certificate exists, so the deliverable is a documented, defensible program and a completed risk analysis.
143 requirementsThe card-brand standard for anyone who stores, processes, or transmits cardholder data. Identical worldwide.
60 obligationsEU privacy law with extraterritorial reach. Applies the moment you handle personal data of people in the EU.
45 obligationsCanada's federal private-sector privacy law, built on ten fair information principles.
39 obligationsQuebec privacy reform with real penalties, a mandatory privacy officer, and consent rules stricter than PIPEDA.
60 obligationsRisk-tiered AI regulation. Obligations depend entirely on whether your system is prohibited, high-risk, limited-risk, or minimal.
You can run more than one framework in the same workspace. Where controls overlap, and SOC 2 and ISO 27001 overlap a great deal, evidence you attach once counts for both.
Vanta and Drata are good products and thousands of companies get certified with them. They are not what this is, and pretending otherwise would waste your time.
Breadth. Hundreds of pre-built integrations covering endpoints, HR systems and tools this does not reach, maintained by teams who do only that. If your control set spans a large estate, that coverage is worth paying for. They also have deep auditor networks and years of integration work behind them.
It connects to fewer systems. Seven are built in, and anything else with an API has to be described as a check rather than picked from a list. There is no endpoint agent and no HR integration. If you need a control watched on every laptop, or evidence pulled from your HRIS, buy one of them. We work alongside them and will say so when that is the right call.
Short version: if your estate is large enough to need hundreds of integrations, endpoint agents and HR coverage, buy a platform. If you need to understand what a framework requires, work through it honestly, have the systems you do run checked daily, and have someone who can close the hard gaps, start here. Plenty of teams end up doing both.
If you already advise clients on security or IT, compliance is the question you keep getting asked and the one you have no tooling for. There is a white-label partner tier for that.
Your client can invite you into their workspace with an auditor role. It is genuinely read-only: every mutating control is hidden, not just disabled.
It costs the auditor nothing and it does not require the client to be a TrazTech customer. If you are an audit firm and want a walkthrough before you suggest it to a client, book a call.
Email address and a company name. We email you a one-time sign-in link, so there is no password to invent. No card at any point.
Five or six questions that decide which controls actually apply to you. This is where a 155-requirement framework often becomes a much shorter list.
Met, partially met, not met, or not applicable, with a note on how. Most teams get a first honest pass done in two or three sittings. You will not finish in an afternoon, and anyone who tells you otherwise is selling something.
You get a readiness score, a ranked gap list with effort estimates, and a starting policy set. From there you either work through it yourself, which is fine, or you ask us for help with the parts you would rather not do.
Free workspace, 10 frameworks, 783 requirements explained in plain English. If you would rather talk it through with a human before you start, that is free too.
Already have a workspace? Sign in.
Yes. No credit card, no trial countdown, no locked features. Everything is open from the moment you create a workspace. We make money when a team wants help closing the gaps the platform finds. The platform itself is not the product we sell.
It is free with no annual contract, every control is written out in plain English rather than assuming you know it, and there is a firm behind it that can do the remediation, not only report on it. It connects to AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira, and to any other system with an API you can describe a check against. Those checks run daily and file evidence against the control they prove. What Vanta and Drata have that this does not is breadth: hundreds of pre-built integrations, endpoint and HR coverage, and years of work behind them. If you need that breadth, buy one of them.
Currently 10: SOC 2, ISO 27001, ISO 42001, NIST CSF 2.0, HIPAA, PCI DSS v4.0.1, GDPR, PIPEDA, Quebec Law 25, EU AI Act. That is 783 individual controls, criteria, and obligations, each written out in plain English.
Your workspace is yours. Assessments, evidence, policies, and risks are scoped to your organisation and are not shared with anyone else. Sign-in is passwordless with short-lived one-time links, so there is no password to leak. You can export your work and you can ask us to delete the workspace.
Yes. You can invite an auditor to your workspace with a read-only role. They can read every assessment answer, open the evidence attached to each control, and see your policies and their approval history, and they cannot change anything. It is meant to replace the shared drive of screenshots that most audits still run on.
Yes. There is a white-label partner tier where you run client workspaces under your own brand, with your logo and domain, and keep the client relationship. Details are on the partners page.
No, and no tool can. A self-assessment tells you where you stand against a framework and what evidence you still owe. Certification or attestation comes from an independent auditor or certification body reviewing your actual controls and evidence. The platform is built to get you to that review with far less pain, not to replace it.