Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Got questions?

General Questions
What types of companies do you work with?
We work with B2B software companies, and the range is wider than people assume: pre-seed startups with a first enterprise prospect asking for a report, established SMEs, and larger organisations running several frameworks at once. Recent work includes a data centre operator of around twenty people and a VC-backed medtech company. There is no minimum stage and no minimum headcount. What matters is whether security or compliance is on your critical path.
How quickly can you start?
Usually within one to two weeks of signing. Readiness engagements run to a fixed window: our SOC 2 track is 75 days of preparation, and we have hit that window every time we have run it. If you have an audit date or a buyer deadline already, tell us what it is and we will say plainly whether it is achievable rather than agreeing and hoping.
What makes traztech different from other consulting firms?
Two things. The work is led by a published vulnerability researcher with five CVEs, including a CVSS 9.1 in the Mirai botnet, so the security advice comes from someone who finds these problems rather than reads about them. And the prices are fixed and published: you can see the number before you speak to anybody. Most firms in this space quote hours and tell you the total afterwards.
Pricing & Engagement
How do you structure your pricing?
Fixed scope, fixed price, published on our pricing page. Readiness sprints start from $3,000, penetration testing and larger programmes are scoped to a defined deliverable, and retainers are monthly where ongoing cover genuinely makes sense. We do not bill hourly. Any third-party auditor or certification body fee is separate and paid directly to them, which we say up front because it is the line that surprises people.
What's your minimum engagement period?
There is no minimum for project work. A gap analysis, a penetration test or a readiness sprint is a defined piece of work with an end. For ongoing security leadership we suggest three months, simply because less than that rarely changes anything, but nothing locks you in beyond the work you have agreed.
Services & Expertise
Do you offer fractional CISO, CTO or COO?
We provide fractional CISO only. That is security leadership: owning your security programme, handling questionnaires and buyer reviews, running incident response readiness, and being accountable for the roadmap. We no longer offer fractional CTO or COO services. If your gap is engineering leadership rather than security, we would rather tell you that than sell you the nearest thing we have.
Can you help with SOC 2 compliance?
Yes, and it is the single thing we are asked for most. SOC 2 in 75 Days covers readiness, remediation and dealing with the auditor inside a set window. Our founder previously took a venture-backed company from no compliance programme at all to a SOC 2 Type II across 76 controls with zero exceptions. We also run ISO 27001, HIPAA, PCI DSS, CPCSC, NIST CSF and the Canadian privacy stack, and frequently run two frameworks together where the overlap makes that cheaper than doing them in sequence.
Can you fail a SOC 2 audit?
Yes, though not as a pass or fail stamp. A CPA firm issues an opinion, and both an adverse opinion and a disclaimer are real, damaging outcomes. ISO 27001 is blunter still: a major nonconformity at Stage 2 withholds the certificate until the fix is verified, at audit days you pay for. The outcome that catches most unprepared companies is worse than a bad report. The auditor reaches fieldwork, finds the evidence is not testable, and recommends pausing, so you have paid for an audit that produced nothing you can send a buyer, re-entering fieldwork means paying a firm again, and a Type II gap can add a fresh three to twelve month observation window. What a stalled audit costs.
Our compliance dashboard is all green. Do we still need help?
Green means the checks the platform can automate are passing. A platform reads your cloud configuration and your device fleet. It cannot confirm that your access review actually ran with a named reviewer, that your incident response plan has ever been tested, or that the change management policy you uploaded describes how your team really deploys. Those gaps are where exceptions get written, and closing them is still work a person has to do.
Do you provide ongoing support or just one-time projects?
Both. Most companies start with one defined piece of work, a gap analysis or a readiness sprint, and some continue into an ongoing arrangement such as fractional CISO cover, vulnerability management or an incident response retainer. Neither requires the other. A one-off engagement is a complete piece of work, not a trial.
What technologies and tools do you work with?
We work across AWS, GCP and Azure, the usual identity providers, and whatever your stack already is. We are not reselling a compliance platform: our workspace is free to use, holds the control sets, evidence register and policy templates, and you keep it whether or not you work with us. If you already run a commercial compliance tool we will work inside it.
Getting Started
What's your onboarding process?
A short scoping conversation, then a written proposal with the scope, the deliverable, the timeline and the price. Once accepted, we run a kickoff, agree the boundary of what is in scope, and issue the evidence request list. On a recent medtech engagement that list ran to 84 items, which is typical rather than unusual, and it is the point at which most companies learn what their real position is.
How do you measure success?
By whether the thing you needed happened. A report issued without exceptions. A questionnaire that stops blocking a deal. A penetration test with findings that got fixed rather than filed. We agree what that looks like before starting, and if we do not think a fixed scope will get you there, we say so on the call and quote it properly instead.
Do you sign NDAs and work contracts?
Yes. We sign mutual NDAs, work under your MSA if you have one, and have our own agreement if you do not. Everyone working on your engagement is bound by confidentiality obligations, and for security work we will also sign whatever scope authorisation your side needs before anything is tested.
No questions match your search. Try different keywords or contact us directly.

Still have questions?

We would love to hear from you. Book a call and let's talk about what you need.

The same work, without the line item

Every readiness programme needs a control library, an evidence register, policies and a score for the board. Being quoted five figures a year for that is normal. Paying it is not.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote $11,000 off a five-figure quote on one engagement, for a documented readiness position Nothing. The audit firm prices your readiness, not your tooling

Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.