Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

SOC 2 Type I vs Type II

A SOC 2 Type I report attests that your security controls are designed correctly at a single point in time. A SOC 2 Type II report attests that those same controls operated effectively over a period, usually three to twelve months. Type II is harder to earn and is what most enterprise buyers ultimately require.

In practice

Type I is a snapshot. It answers "are the right controls in place today?" and is faster to obtain, which makes it useful for unblocking a deal that is stalling on the security review.

Type II is a track record. The auditor samples evidence across the observation window to confirm controls ran consistently, not just on audit day. The common path is to earn Type I first, then run a Type II observation period immediately after.

// how traztech helps

traztech delivers SOC 2 Type I and Type II delivery for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.