Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

CVE (Common Vulnerabilities and Exposures)

A CVE, or Common Vulnerabilities and Exposures identifier, is a unique public reference number assigned to a specific, publicly disclosed security vulnerability. The format is CVE-YYYY-NNNN, and the system is coordinated by MITRE. CVEs give vendors, researchers, and defenders a shared name for the same flaw.

In practice

When a CVE is published it usually appears in the National Vulnerability Database (NVD) with details, affected products, and a CVSS severity score. Scanners and patch tools key off CVE IDs to tell you what you are exposed to.

A CVE identifies the flaw but does not by itself measure its danger; that is what the CVSS score adds. traztech's founder has five published CVEs, including CVE-2024-45163, a CVSS 9.1 kill-switch for the Mirai botnet.

// how traztech helps

traztech delivers security research and CVE disclosure for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

CVEs show up in three places in a compliance programme: scanner output, vendor advisories, and the question of whether you patch inside your own stated timeframe.

The number itself is only an identifier. What matters for a control is whether you learned about it, decided how it applied to you, and acted within the window your policy commits to.

CVE (Common Vulnerabilities and Exposures): common questions

Who assigns CVE identifiers?

CVE Numbering Authorities, coordinated by MITRE. Vendors, research organisations and coordination centres can all act as CNAs.

Does every vulnerability get a CVE?

No. CVEs cover publicly known vulnerabilities in released software. An issue in your own unreleased code or configuration will not have one, which is why scanner output is not the whole picture.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.