Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

CVE (Common Vulnerabilities and Exposures)

A CVE, or Common Vulnerabilities and Exposures identifier, is a unique public reference number assigned to a specific, publicly disclosed security vulnerability. The format is CVE-YYYY-NNNN, and the system is coordinated by MITRE. CVEs give vendors, researchers, and defenders a shared name for the same flaw.

In practice

When a CVE is published it usually appears in the National Vulnerability Database (NVD) with details, affected products, and a CVSS severity score. Scanners and patch tools key off CVE IDs to tell you what you are exposed to.

A CVE identifies the flaw but does not by itself measure its danger; that is what the CVSS score adds. traztech's founder has six published CVEs, including CVE-2024-45163, a CVSS 9.1 kill-switch for the Mirai botnet.

// how traztech helps

traztech delivers security research and CVE disclosure for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.