A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →The EU AI Act is real, and its obligations for high-risk systems (the Annex III categories) are phasing in through 2026.
If you build or deploy AI that touches EU users, we help you figure out whether you’re in scope, what conformity-assessment work applies, and how to get ready without boiling the ocean.
You walk away knowing exactly whether the EU AI Act applies to you, which obligations bite, and a concrete plan to close the gaps, instead of guessing or ignoring a regulation that is already phasing in.
The price above covers the work. It also covers where the work lives, which most buyers are quoted separately as an annual platform subscription.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
Yes. It is a real EU regulation with obligations phasing in over time. Requirements for high-risk (Annex III) systems are among those phasing in through 2026. We help you get ready ahead of the applicable deadlines rather than react to them.
High-risk categories are defined in Annex III and cover uses like employment, creditworthiness, biometrics, and critical infrastructure. Our scoping call walks your systems against those categories so you get a clear in-scope or out-of-scope answer.
It can. The Act reaches providers and deployers whose AI systems affect people in the EU, regardless of where the company is based. Scoping is the first thing we do, so you do not spend on remediation you do not need.
It varies by the number and complexity of your AI systems and how much documentation already exists. We scope it on a discovery call and point you to pricing rather than quoting a number blind.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Book a free 30-minute call, or send an inquiry. We’ll tell you whether it fits, what it costs, and when we can start.