Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Penetration Test vs Vulnerability Scan

A vulnerability scan is an automated tool that lists known weaknesses across systems, while a penetration test is a manual engagement where a human actively exploits weaknesses to prove real-world impact. Scans give breadth and run continuously; pen tests give depth and validation. Most mature security programs use both.

In practice

Think of the scan as a smoke detector and the pen test as a fire drill. The scan tells you where the risk likely is, cheaply and often. The pen test confirms what an attacker could actually do with it.

Compliance language sometimes blurs the two, so read requirements carefully. PCI DSS, for example, mandates both regular scanning and an annual penetration test, and they are not interchangeable.

// how traztech helps

traztech delivers scoping the right security testing for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.