Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Cookie Policy

Last updated: April 28, 2026

This page explains what cookies and similar technologies traztech.ca uses, why we use them, and how you can control them. We aim to be straightforward. No fine print buried under legalese.

What is a cookie

A cookie is a small text file a website stores on your device. Cookies are how a browser remembers things between page loads: your login session, your preferences, what page you came from. We also use related browser storage (localStorage, sessionStorage) for the same purpose.

What we set ourselves

traztech.ca sets a small number of first-party items on your browser:

  • tt-theme, stored in localStorage. Remembers your light/dark mode choice. Not a cookie. We never read it server-side.
  • Session cookies on logged-in apps. If you sign in to the Workspace at /portal, or to /clarity or /reskillix, those products set a standard session cookie so you stay logged in. The platform session cookie is named traztech_portal. It is HttpOnly, SameSite=Lax, and secure over HTTPS.
  • Analytics cookies. Google Analytics and Microsoft Clarity set first-party cookies on the marketing site (_ga, _ga_*, _clck, _clsk). See the analytics section below for what they do.

We do not set advertising or retargeting cookies, and we do not sell or share what we collect with ad networks. The Workspace itself carries no analytics: /portal runs neither Google Analytics nor Clarity, and every page there is noindex.

Third parties that may set cookies

A few third-party services run on our pages. They may set their own cookies under their own privacy policies. We don't control them, but we'll tell you who they are and why they're here:

  • Cloudflare is our CDN and edge security layer. It sets cookies like __cf_bm and cf_clearance to distinguish humans from bots and protect against abuse. Cloudflare cookie policy.
  • Tawk.to powers the live chat widget at the bottom of the page. It sets cookies to maintain your chat session and remember chat history. Tawk.to privacy policy.
  • Google Analytics 4 measures which pages get read and which do not. It sets _ga and _ga_* cookies. We have IP anonymisation on and we do not enable Google Signals, advertising features, or remarketing. Google privacy policy.
  • Microsoft Clarity records anonymised session replays and heatmaps so we can see where a page confuses people. It sets _clck and _clsk cookies. Clarity masks text input by default, so what you type into a form is not captured. Microsoft privacy statement.
  • Google Fonts and CDN assets. We load fonts from Google and Bootstrap/Font Awesome from public CDNs. Standard CDN logging applies.

Analytics, and why there is no banner today

We run two analytics tools on the marketing site: Google Analytics 4 and Microsoft Clarity. Both set first-party cookies. We use them to understand which pages are useful, not to build a profile of you, and we do not run advertising trackers, retargeting pixels, or cross-site ad audiences.

Being straight with you, since we sell compliance advice and it would be poor form to be vague here: analytics cookies are not strictly necessary cookies. Under the GDPR and the ePrivacy Directive, a visitor in the EEA or the UK should be asked for consent before they are set. We do not currently show a consent banner, so if you are visiting from the EEA or the UK and you would rather not be measured, block third-party and analytics cookies in your browser or use the opt-outs below. We are working on a proper consent flow for those visitors. In Canada, PIPEDA and Quebec Law 25 permit this use on an implied-consent basis given the disclosure on this page.

To opt out directly: install the Google Analytics opt-out add-on, and see Microsoft Clarity's cookie guidance. Blocking either changes nothing about how the site works for you.

How to control cookies

You're in charge of your browser. Every modern browser lets you clear cookies, block them per-site, or block third parties entirely:

Blocking everything won't break the marketing site. It may break the chat widget and form submissions.

Do Not Track

Do Not Track was never adopted as a standard and most vendors ignore it, including Google Analytics and Microsoft Clarity. We are not going to claim we honour a signal that our analytics providers disregard. If you want to be certain you are not measured, block analytics and third-party cookies in your browser, or use the opt-outs listed above. That works regardless of what any vendor chooses to respect.

Global Privacy Control is a different matter, and where it carries legal weight we will treat it as a valid opt-out signal as we build out our consent handling.

Changes to this policy

If we add a new third-party service or change how something works, we'll update the date at the top of this page. We don't email about cookie policy changes. Checking back here is the canonical source.

Contact

Questions or want a specific cookie excluded? Email [email protected] or use the form at traztech.ca/contact. If you're evaluating a vendor for SOC 2 or ISO 27001 readiness, this policy is also part of what an auditor reviews.