Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Penetration Testing

Penetration testing is an authorized, manual security assessment in which testers actively try to exploit weaknesses in an application, network, or system the way a real attacker would. Unlike an automated scan, a pen test chains vulnerabilities together and validates real impact. The output is a report of confirmed, exploitable findings ranked by risk.

In practice

A pen test answers "can someone actually break in, and how far can they get?" Skilled testers find logic flaws, broken access controls, and chained exploits that scanners miss entirely.

Pen tests are scoped engagements: web app, external network, internal network, cloud, or API. Enterprise customers, SOC 2 auditors, and cyber insurers frequently require an annual pen test as evidence.

// how traztech helps

traztech delivers penetration testing scoped to your real threat model for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A penetration test is usually triggered by somebody else asking for one. An enterprise buyer, an auditor, a cyber insurer or a framework requirement. That matters because the reason determines the scope: a test to satisfy PCI DSS looks different from a test to reassure a customer about a new feature.

The deliverable people undervalue is the retest. A report full of findings proves you looked. Evidence that the findings were fixed and verified is what an auditor and a buyer actually want to see.

Penetration Testing: common questions

How often should we run a penetration test?

Annually is the common baseline, and most frameworks expect at least that. Significant architecture changes or a major new feature usually justify an additional test rather than waiting for the yearly cycle.

What is the difference between a penetration test and a vulnerability scan?

A scan is automated and finds known issues at scale. A penetration test is human-led and chains issues together to show real impact. They answer different questions and most programmes need both.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.