Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Most of what we sell is fixed-scope work with an end date. This is the other half: what has to keep happening afterwards. Continuous compliance, your security program, and incident response, held by the people who built the thing they are now keeping true.
The usual shape of ongoing compliance is a consultant plus an annual subscription for somewhere to keep the evidence. You are quoted twice for one programme. traztech Workspace comes with the retainer, and if you already run a compliance platform we work in that instead.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Most retainers mix all three. A company keeping a Type II alive usually also wants the questionnaires answered and someone to call when something breaks, so splitting that into separate contracts would be tidy on an invoice and wrong in practice.
The controls keep operating and keep producing dated evidence, so the next audit is a review rather than a rebuild.
What that means →Someone senior accountable for the program: risk, roadmap, policies, questionnaires, and the board conversation.
What that means →Incident command, containment, postmortem and disclosure, with tabletops between incidents.
What that means →A SOC 2 Type II attests that your controls operated across a period, which means the period has to be operated. ISO 27001 brings a surveillance audit every year and a recertification every three. PCI DSS, HIPAA, PIPEDA and Law 25 all carry recurring obligations nobody is reminded about until an auditor asks for the last four quarters of them at once. This is the work that makes the next audit uneventful, and audits stall almost entirely because it stopped.
A security program is what your policies, your risk register and your controls are supposed to add up to. Most companies at this stage have the artefacts and no owner, which is how you end up with a policy set nobody follows and a risk register last touched during the audit. This is the fractional or virtual CISO shape: a named person accountable for the program, its roadmap, and the conversations it has to survive.
traztech Workspace is included: control libraries with every requirement in plain English across 14 frameworks, the evidence register, 40 policy templates with approval history, the risk register, vendor questionnaires, the compliance calendar and readiness scoring, with read-only access for your auditor. It is the same register we work from, so a requested artefact lands against the control it evidences. If your evidence already lives somewhere else, in a compliance platform you bought or across Jira, Drive and a ticket queue, that is where we work. Either way you keep the record when the retainer ends.
The evidence register maps each artefact to every control that asks for it, across every framework you are doing. Upload the access review once and it is attached wherever it belongs, instead of once per audit.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
Everything else on this site publishes a fixed price, because a fixed scope can carry one. Ongoing work cannot honestly be reduced to a single figure on a page: the monthly load for one framework and eight people is not the load for three frameworks, a vendor programme and an on-call rotation. So the number comes out of a scoping call, with the reasoning attached.
What you are running, what is already in place, what is coming (an observation window, a surveillance audit, an enterprise deal with a security review attached), and who internally owns any of it today.
What we would do in the first month, what settles into the monthly cadence, and what you should keep in-house. Where we think a retainer is not the right answer yet, that is what the document says.
Priced from the work in the plan, with what is in and what is out stated in the same document. No tiers to reverse-engineer and no per-seat maths.
The scope, the number and the plan arrive together. If the answer is a one-off project instead, or nothing at all this quarter, we would rather you knew that before signing than four months in.
Every other price on this site is one we publish and stand behind. We would rather leave this one as a figure you get in writing than print a number we would have to walk back on the call, which is the thing we criticise other firms for doing.
Incident response used to be its own retainer with its own tiers. It is part of this now, because the companies buying it were buying the rest as well. Credentials in a public repo, a customer reporting an exploit, a cloud account locked out: the worst time to look for an incident responder is during an incident, while you negotiate scope and rates with a stranger and the clock runs.
A one-day incident response tabletop is still a fixed-scope engagement with a published price, and it is the usual first step. Most teams have a much clearer view of what they need on retainer afterwards.
Written to be useful whether or not you hire anyone, including the parts where a retainer is the wrong purchase.
One call, then a written scope, a monthly number and a plan of approach. If a retainer is not the right answer for you yet, the document will say so.
Retainers start in the four figures a month. We do not publish a single floor because the work is not a single thing: a company keeping one SOC 2 report alive is a different monthly load from one running two frameworks, a vendor programme and an on-call rotation. You get the number, the scope it covers and the plan of approach in writing after one scoping call, before anything is signed.
Keeping a framework true after the report is issued. A SOC 2 Type II attests that controls operated across a period, so the access reviews, the vulnerability scans, the training, the vendor reviews and the policy approvals have to keep happening and keep producing dated evidence. Continuous compliance is somebody owning that cadence and the evidence it produces, rather than reconstructing a year of it the month before fieldwork.
Security program ownership is one of the shapes a retainer takes, and for many companies it is what they mean when they ask for a fractional or virtual CISO. The difference is only that you are not buying a title and a fixed number of hours. You are buying the outcome the program is supposed to produce, with a named person accountable for it.
There is nothing to buy. traztech Workspace comes with the engagement: control libraries, the evidence register, policy templates, the risk register, vendor questionnaires and readiness scoring. If you already run a compliance platform, or your evidence lives in Jira, Drive and a ticket queue, we work in what you have.
We anchor the term to something real, usually an observation period, a certification cycle or a fixed number of months, and bill monthly against it. It renews with a conversation rather than silently, because a retainer nobody notices renewing is one nobody is getting value from.
A defined response path before something goes wrong: an agreed escalation process, prepared runbooks, and reserved access to responders when you need them. It covers triage, containment guidance and coordination during an incident, plus the readiness work between incidents. Response targets are set in the agreement so the expectation is written down rather than assumed.
During an active incident, hours matter, and onboarding a stranger to your environment is slow and risky. A retainer means the contracts, the access and the runbooks already exist. It is also what your enterprise security questionnaire and your cyber insurer are asking about when they ask whether you have a retained incident response capability.
No. We run incident command so your engineers can work the technical problem instead of also managing the bridge call, the status page and the customer comms.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.