Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

DAST (Dynamic Application Security Testing)

DAST, or Dynamic Application Security Testing, tests a running application from the outside by sending crafted inputs and observing responses, without access to source code. It is a black-box technique that finds vulnerabilities visible at runtime, such as authentication and injection flaws. DAST mimics how an external attacker probes a live system.

In practice

DAST validates the application as deployed, configuration and all, so its findings tend to be real and exploitable rather than theoretical. It does not depend on the language the app is written in.

The trade-off is that DAST runs later in the lifecycle and cannot point to the offending line of code the way SAST can. The two are complementary, which is why mature pipelines run both.

// how traztech helps

traztech delivers secure CI/CD pipeline setup for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.