Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Quebec Law 25

Quebec Law 25 is the province's modernized private-sector privacy law, which significantly strengthened how organizations collect, use, and protect personal information about Quebec residents. It introduced mandatory breach reporting, privacy-by-default, consent rules, and transparency around automated decision-making. Its requirements phased in through 2022, 2023, and 2024.

In practice

Law 25 requires organizations to appoint a person responsible for privacy, run privacy impact assessments for certain projects, and report confidentiality incidents that pose a risk of serious injury to the regulator (the CAI) and affected individuals.

Section 12.1 requires meaningful disclosure when a decision is based exclusively on automated processing, which directly affects AI products. Penal fines can reach 25 million CAD or 4 percent of worldwide turnover, with administrative monetary penalties capped at 10 million CAD or 2 percent.

// how traztech helps

traztech delivers Quebec Law 25 readiness sprints for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

Law 25 tends to surface when a Quebec-based customer sends their DPA, or when somebody notices the private right of action and asks whether the company is exposed.

The obligations that catch people out are the privacy officer designation, the requirement to conduct privacy impact assessments for certain projects, and the rules around transfers outside Quebec.

Quebec Law 25: common questions

Does Law 25 apply if we are not in Quebec?

Yes, if you handle personal information of people in Quebec. Establishment is not the test.

How is Law 25 different from PIPEDA?

Law 25 is more prescriptive and carries significantly heavier penalties, plus a private right of action. Where both apply, meeting Law 25 generally covers the PIPEDA baseline.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.