Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Version 1.1 · effective August 30, 2026
The short version. These are the processor terms for traztech Workspace. You are the controller of what you put in it. We process it to prepare and evidence your audit, on your instructions, and for nothing else.
You do not need to send us a data processing agreement to sign. This schedule is incorporated into the engagement, and a copy of it is filed against our record in your own supplier register the day your workspace is created, so that row arrives complete.
It is versioned. When these terms change the version changes, the previous document stays on your file, and every workspace is re-issued rather than the text quietly moving underneath you.
TrazTech Inc. and the Customer
Version 1.1 · effective 30 August 2026
This schedule forms part of the engagement between the parties and governs personal data processed by TrazTech while providing audit preparation services. It is a standing term: it is published at https://traztech.ca/dpa and incorporated rather than negotiated per engagement, and it is versioned so a change is visible rather than silent. The published copy and this one are rendered from the same source, so they cannot disagree.
the Customer is the controller. TrazTech is a processor acting on documented instructions, which are the engagement scope and anything given in writing during delivery. TrazTech does not determine the purposes of the processing and does not process the data for its own purposes.
TrazTech does not receive your production data, your customers' data, or special categories of personal data. Screening is recorded as a completion date and method; the underlying report stays with you.
Processing is limited to preparing, evidencing and supporting your audit, and lasts for the engagement plus the retention period below.
Servers in Toronto, Canada, on Akamai Connected Cloud, with Cloudflare in front. The origin accepts traffic only from Cloudflare. Data is not transferred outside Canada in the ordinary course of the service.
Akamai Connected Cloud (hosting, Canada), Cloudflare (edge protection and DNS), and SendGrid (transactional email). TrazTech remains responsible for their acts and omissions. You will be told before a new sub-processor handling your personal data is added, and may object.
Everyone at TrazTech with access is bound by written confidentiality obligations that survive the end of their engagement.
TrazTech will assist with data subject requests, impact assessments and regulator enquiries so far as the data it holds allows, and will notify you without undue delay, and in any case within 72 hours, on becoming aware of a personal data breach affecting your data.
You can export every register and download every uploaded file at any time, without a request or a waiting period. On written request, or within 90 days of the engagement ending, the workspace and its contents are deleted, save where retention is required by law.
TrazTech will make available the information reasonably necessary to demonstrate compliance with this schedule, and will accept a documented security questionnaire once per year. TrazTech does not currently hold its own SOC 2 or ISO 27001 report, and says so plainly rather than implying otherwise.
TrazTech sits outside the Customer's system boundary: it operates no control that the Customer's service commitments depend on, and is therefore neither carved out of nor included in the system description. It is listed on the supplier register because supplier management (ISO 27001 A.5.19, A.5.20 and A.5.22; SOC 2 CC9.2) covers third parties with access to information. ISO 27001 A.5.21 does not apply: this is a professional service, not an ICT supply chain product.
Anything about this schedule, a data subject request, or a security question before you put data in the platform: [email protected]. Suspected vulnerabilities go to [email protected], and we will not threaten anyone who reports one in good faith.
Related: privacy policy, how the platform handles your data, terms of service.