A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Data residency is the question of which country or region your data is physically stored and processed in. It is distinct from data sovereignty, which is about whose laws apply to that data. Residency matters because contracts, sector rules, and some public-sector buyers require that certain data stay within Canada, or within a named jurisdiction.
The first task is always an honest map. Primary storage is easy; the misses are backups, log aggregation, analytics, and support tools that quietly move data to another region. A residency claim is only as good as that inventory.
Most cloud providers let you pin workloads to Canadian regions, which satisfies many residency requirements directly. Where a buyer's real concern is sovereignty rather than location, that needs to be surfaced early, because pinning a region does not answer it.
traztech delivers compliance and privacy readiness for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
Data residency comes up in procurement and in privacy reviews, usually as a flat requirement: this data must stay in Canada. Canadian public-sector and health buyers raise it most, and the honest answer depends on knowing where every copy of the data actually lives, including backups and logs. We cover it within compliance and privacy readiness.
The complication is that residency and sovereignty are not the same. Data stored in Canada can still be subject to foreign law if the provider is foreign-owned, so a residency commitment answers where the data sits, not who can compel access to it.
Not as a blanket rule. Some public-sector and health-sector obligations and many contracts require Canadian residency for specific data, and Quebec Law 25 adds assessment requirements before transferring personal information outside Quebec, but there is no single federal data-localisation law for the private sector.
Residency is where the data physically is. Sovereignty is whose laws can reach it. A foreign-owned provider hosting in Canada satisfies residency while leaving a sovereignty question open.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.