Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

SOC 2

SOC 2 is an auditing standard from the AICPA that reports on how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A licensed CPA firm performs the audit and issues an attestation report. Software and SaaS vendors use SOC 2 reports to prove their security controls to enterprise customers.

In practice

In practice, SOC 2 is the report enterprise buyers ask for before they sign. Their procurement and security teams read the report instead of running their own audit of your environment, so a clean SOC 2 shortens sales cycles.

The security criterion (the Common Criteria) is mandatory; the other four are optional and scoped to what your product actually does. Most startups start with a Type I covering security only, then add a Type II observation period and additional criteria as customers demand them.

// how traztech helps

traztech delivers SOC 2 readiness and audit coordination for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

SOC 2 shows up first as a line in a procurement email, usually phrased as "can you send us your SOC 2 report". What the buyer means is a current Type II from a licensed CPA firm, delivered under NDA. A Type I will often get you into the conversation, but the follow-up question is when the Type II lands.

Inside an engagement, SOC 2 is not one thing to do. It is a scope decision, a control set, an observation window and an evidence habit. The scope decision is the one that carries the rest: which systems, which criteria beyond Security, and which dates the window covers.

SOC 2: common questions

Is SOC 2 a certification?

No. SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls and issues an opinion in a report. Nobody issues a certificate, and there is no logo you are entitled to display the way there is with ISO 27001.

How long is a SOC 2 report valid?

A Type II report covers a stated observation period and buyers generally expect one no older than twelve months. That is why SOC 2 becomes an annual cycle rather than a one-off project.

Do we need all five Trust Services Criteria?

No. Security, the Common Criteria, is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional and should be scoped to what your product actually does and what your buyers ask about.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.