Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

PCI DSS

PCI DSS, the Payment Card Industry Data Security Standard, is a set of security requirements for any organization that stores, processes, or transmits payment card data. It is mandated by the major card brands and enforced through contracts with payment processors and banks. Compliance is validated annually, with requirements scaled to transaction volume.

In practice

The single most effective PCI move is to shrink scope: by routing card data through a compliant payment processor and never touching it directly, most companies sharply reduce what they have to secure and document.

Validation ranges from a Self-Assessment Questionnaire for smaller merchants to an audit by a Qualified Security Assessor for the largest. PCI DSS explicitly requires both regular vulnerability scanning and annual penetration testing.

// how traztech helps

traztech delivers PCI DSS scoping and readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

PCI DSS work almost always starts in the wrong place. Teams begin with controls before establishing their SAQ type, when the SAQ type determines how much of the standard applies at all.

Scope reduction saves more than any control implementation. Moving card data out of your environment, through a hosted page or an iframe, changes which questions you have to answer rather than how well you answer them.

PCI DSS: common questions

Does using Stripe mean we are PCI compliant?

It reduces your scope substantially but does not remove the obligation. You still complete and attest to a Self-Assessment Questionnaire, and if anything on your side ever touches a card number the picture changes.

Which version applies now?

PCI DSS v4.0.1, and several requirements that were future-dated have since come into force, so an assessment from a couple of years ago will be out of date.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.