Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Ongoing work · one door

Keep the program running,
not just the project.

Most of what we sell is fixed-scope work with an end date. This is the other half: what has to keep happening afterwards. Continuous compliance, your security program, and incident response, held by the people who built the thing they are now keeping true.

From $X,XXX/m CAD · scoped and priced to your environment
Talk to us about a retainer How we price it
$0 Tooling licence. The workspace is part of the engagement, not a line on top of it.
$11,000 Off an audit quote on one engagement, for a documented readiness position. How that worked.
14 Frameworks in scope, run side by side, with evidence collected once and counted everywhere.
1 call To a written scope, a monthly number and a plan of approach. Nothing signed before you have all three.

There is no platform to buy on top of this

The usual shape of ongoing compliance is a consultant plus an annual subscription for somewhere to keep the evidence. You are quoted twice for one programme. traztech Workspace comes with the retainer, and if you already run a compliance platform we work in that instead.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote $11,000 off a five-figure quote on one engagement, for a documented readiness position Nothing. The audit firm prices your readiness, not your tooling

Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.

Three shapes, one agreement

Most retainers mix all three. A company keeping a Type II alive usually also wants the questionnaires answered and someone to call when something breaks, so splitting that into separate contracts would be tidy on an invoice and wrong in practice.

The report is issued. The obligations are not over.

A SOC 2 Type II attests that your controls operated across a period, which means the period has to be operated. ISO 27001 brings a surveillance audit every year and a recertification every three. PCI DSS, HIPAA, PIPEDA and Law 25 all carry recurring obligations nobody is reminded about until an auditor asks for the last four quarters of them at once. This is the work that makes the next audit uneventful, and audits stall almost entirely because it stopped.

Every month
  • Access reviews and offboarding evidence, dated and named
  • Vulnerability scan triage and remediation tracking
  • Evidence register kept current against every control it proves
  • Working session, with a written record of what moved
Every quarter
  • Vendor and third-party risk reviews, tiered by the data they touch
  • Policy review and re-approval, with version history
  • Risk register reassessed with owners and treatments
  • Tabletop or recovery test, which doubles as the evidence
Every year
  • Penetration test scoped, run and retested
  • Security awareness training, with completion records
  • Business continuity and disaster recovery exercise
  • The audit or surveillance cycle handled end to end

Someone senior accountable for security

A security program is what your policies, your risk register and your controls are supposed to add up to. Most companies at this stage have the artefacts and no owner, which is how you end up with a policy set nobody follows and a risk register last touched during the audit. This is the fractional or virtual CISO shape: a named person accountable for the program, its roadmap, and the conversations it has to survive.

It comes with the engagement

traztech Workspace is included: control libraries with every requirement in plain English across 14 frameworks, the evidence register, 40 policy templates with approval history, the risk register, vendor questionnaires, the compliance calendar and readiness scoring, with read-only access for your auditor. It is the same register we work from, so a requested artefact lands against the control it evidences. If your evidence already lives somewhere else, in a compliance platform you bought or across Jira, Drive and a ticket queue, that is where we work. Either way you keep the record when the retainer ends.

Collect the evidence once

The evidence register maps each artefact to every control that asks for it, across every framework you are doing. Upload the access review once and it is attached wherever it belongs, instead of once per audit.

No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.

A number, and the plan it is based on

Everything else on this site publishes a fixed price, because a fixed scope can carry one. Ongoing work cannot honestly be reduced to a single figure on a page: the monthly load for one framework and eight people is not the load for three frameworks, a vendor programme and an on-call rotation. So the number comes out of a scoping call, with the reasoning attached.

01

One scoping call

What you are running, what is already in place, what is coming (an observation window, a surveillance audit, an enterprise deal with a security review attached), and who internally owns any of it today.

02

A written plan of approach

What we would do in the first month, what settles into the monthly cadence, and what you should keep in-house. Where we think a retainer is not the right answer yet, that is what the document says.

03

A monthly number against that scope

Priced from the work in the plan, with what is in and what is out stated in the same document. No tiers to reverse-engineer and no per-seat maths.

04

You decide with the whole picture

The scope, the number and the plan arrive together. If the answer is a one-off project instead, or nothing at all this quarter, we would rather you knew that before signing than four months in.

What the agreement says

WhoA named person
The people who ran your readiness engagement, not a queue or a rotating pool
ScopeWritten, and bounded
What the month covers, what it does not, and what happens when something outside it comes up
TermAnchored to a cycle
Usually an observation period or a certification cycle, billed monthly, renewed in a conversation
Why there is no published floor yet

Every other price on this site is one we publish and stand behind. We would rather leave this one as a figure you get in writing than print a number we would have to walk back on the call, which is the thing we criticise other firms for doing.

When the pager goes off

Incident response used to be its own retainer with its own tiers. It is part of this now, because the companies buying it were buying the rest as well. Credentials in a public repo, a customer reporting an exploit, a cloud account locked out: the worst time to look for an incident responder is during an incident, while you negotiate scope and rates with a stranger and the clock runs.

Who picks up. Five published CVEs, one of them a CVSS 9.1 in the Mirai botnet, plus 20+ penetration tests behind the response.

Getting set up

Week oneContract and access
MSA, SOW, NDA, and read-only access into your cloud, identity provider and observability stack
Week twoRunbook and escalation
Your stack, key contacts, decision authority, and the paths we are reachable on
First 30 daysFirst tabletop
Run on the most likely incident type for your business, which surfaces the gaps in the runbook

A one-day incident response tabletop is still a fixed-scope engagement with a published price, and it is the usual first step. Most teams have a much clearer view of what they need on retainer afterwards.

The work this page describes, in detail

Written to be useful whether or not you hire anyone, including the parts where a retainer is the wrong purchase.

Tell us what you are keeping alive

One call, then a written scope, a monthly number and a plan of approach. If a retainer is not the right answer for you yet, the document will say so.

Talk to us about a retainer See fixed-scope pricing

Questions we get before signing one

What does a retainer with traztech cost?

Retainers start in the four figures a month. We do not publish a single floor because the work is not a single thing: a company keeping one SOC 2 report alive is a different monthly load from one running two frameworks, a vendor programme and an on-call rotation. You get the number, the scope it covers and the plan of approach in writing after one scoping call, before anything is signed.

What is continuous compliance?

Keeping a framework true after the report is issued. A SOC 2 Type II attests that controls operated across a period, so the access reviews, the vulnerability scans, the training, the vendor reviews and the policy approvals have to keep happening and keep producing dated evidence. Continuous compliance is somebody owning that cadence and the evidence it produces, rather than reconstructing a year of it the month before fieldwork.

Is this the same as a fractional CISO?

Security program ownership is one of the shapes a retainer takes, and for many companies it is what they mean when they ask for a fractional or virtual CISO. The difference is only that you are not buying a title and a fixed number of hours. You are buying the outcome the program is supposed to produce, with a named person accountable for it.

Do we have to buy your software?

There is nothing to buy. traztech Workspace comes with the engagement: control libraries, the evidence register, policy templates, the risk register, vendor questionnaires and readiness scoring. If you already run a compliance platform, or your evidence lives in Jira, Drive and a ticket queue, we work in what you have.

What is the minimum term?

We anchor the term to something real, usually an observation period, a certification cycle or a fixed number of months, and bill monthly against it. It renews with a conversation rather than silently, because a retainer nobody notices renewing is one nobody is getting value from.

What does an incident response retainer include?

A defined response path before something goes wrong: an agreed escalation process, prepared runbooks, and reserved access to responders when you need them. It covers triage, containment guidance and coordination during an incident, plus the readiness work between incidents. Response targets are set in the agreement so the expectation is written down rather than assumed.

Why a retainer instead of calling someone when we get hit?

During an active incident, hours matter, and onboarding a stranger to your environment is slow and risky. A retainer means the contracts, the access and the runbooks already exist. It is also what your enterprise security questionnaire and your cyber insurer are asking about when they ask whether you have a retained incident response capability.

Do you replace our engineers during an incident?

No. We run incident command so your engineers can work the technical problem instead of also managing the bridge call, the status page and the customer comms.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.