Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

CVSS (Common Vulnerability Scoring System)

CVSS, the Common Vulnerability Scoring System, is an open framework for rating the severity of a security vulnerability on a scale from 0.0 to 10.0. The score is derived from factors like how a flaw is exploited and the impact on confidentiality, integrity, and availability. Higher scores indicate more severe vulnerabilities.

In practice

CVSS bands map to labels: 0.1 to 3.9 is low, 4.0 to 6.9 medium, 7.0 to 8.9 high, and 9.0 to 10.0 critical. Teams use these scores to decide what to patch first.

The base score reflects the flaw in isolation; it is not a complete picture of your risk. A "critical" CVE on a system with no network exposure may matter less than a "medium" on an internet-facing one, which is why context still drives prioritization.

// how traztech helps

traztech delivers vulnerability triage and prioritization for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.