Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

GDPR

The GDPR, or General Data Protection Regulation, is the European Union's data protection law governing how organizations collect, use, and safeguard the personal data of people in the EU. It grants individuals rights over their data and requires a lawful basis for processing. It applies to any organization handling EU residents' data, regardless of where the organization is based.

In practice

GDPR applies extraterritorially, so a company anywhere can fall under it by serving EU users. Core obligations include a lawful basis for processing, honoring data-subject rights, data protection by design, and breach notification within 72 hours.

Penalties are significant: up to 20 million euros or 4 percent of global annual revenue, whichever is higher. Many of its concepts map closely to other modern privacy laws, including Quebec Law 25.

// how traztech helps

traztech delivers privacy and data-protection readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

GDPR shows up as a DPA to sign, a data subject request you have to answer inside a deadline, or a security questionnaire asking where personal data is stored and who can reach it.

The work that pays off is upstream of policy text: knowing what personal data you hold, where it flows, who processes it on your behalf and what your lawful basis is. Everything else is downstream of that.

GDPR: common questions

Does GDPR apply to a Canadian company?

It can. If you offer goods or services to people in the EU or monitor their behaviour, it applies regardless of where you are established.

What is the difference between a controller and a processor?

A controller decides why and how personal data is processed. A processor acts on the controller's instructions. Most B2B SaaS companies are processors for customer data and controllers for their own staff and prospect data.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.