Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →SOC 2 is an auditing standard from the AICPA that reports on how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A licensed CPA firm performs the audit and issues an attestation report. Software and SaaS vendors use SOC 2 reports to prove their security controls to enterprise customers.
In practice, SOC 2 is the report enterprise buyers ask for before they sign. Their procurement and security teams read the report instead of running their own audit of your environment, so a clean SOC 2 shortens sales cycles.
The security criterion (the Common Criteria) is mandatory; the other four are optional and scoped to what your product actually does. Most startups start with a Type I covering security only, then add a Type II observation period and additional criteria as customers demand them.
traztech delivers SOC 2 readiness and audit coordination for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
SOC 2 shows up first as a line in a procurement email, usually phrased as "can you send us your SOC 2 report". What the buyer means is a current Type II from a licensed CPA firm, delivered under NDA. A Type I will often get you into the conversation, but the follow-up question is when the Type II lands.
Inside an engagement, SOC 2 is not one thing to do. It is a scope decision, a control set, an observation window and an evidence habit. The scope decision is the one that carries the rest: which systems, which criteria beyond Security, and which dates the window covers.
No. SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls and issues an opinion in a report. Nobody issues a certificate, and there is no logo you are entitled to display the way there is with ISO 27001.
A Type II report covers a stated observation period and buyers generally expect one no older than twelve months. That is why SOC 2 becomes an annual cycle rather than a one-off project.
No. Security, the Common Criteria, is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional and should be scoped to what your product actually does and what your buyers ask about.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.