A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A subservice organization is a vendor whose own controls are relevant to the services covered by a company's SOC 2 report, such as the cloud provider that hosts the audited system. The report handles it one of two ways: the carve-out method excludes the subservice organization's controls and names the customer's reliance on them, while the inclusive method folds them in. Most SOC 2 reports use the carve-out method.
When a report carves out a subservice organization, the assurance stops at that boundary. The practical response is to collect the carved-out vendor's own SOC 2 and read its complementary controls, rather than assuming the provider's opinion covered them.
On your own report, the choice is almost always carve-out, because your infrastructure providers already produce their own attestations. Your job is to track those attestations and implement the complementary controls they assume.
traztech delivers third-party risk management for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
The term matters when you read a SOC 2 and see a subservice organization carved out, because it changes what the report actually covers. The provider's clean opinion does not extend to the carved-out vendor, so you are expected to review that vendor's own report separately. Tracking those reports is part of third-party risk management.
When you issue your own report, your major infrastructure providers are usually subservice organizations handled by carve-out. The report then leans on complementary controls at those vendors, which is why their current attestations belong in your own vendor file.
Carve-out excludes the subservice organization's controls from your report and discloses the reliance; inclusive brings their controls into the examination. Carve-out is far more common because it is simpler and most providers already have their own SOC 2.
Related but not identical. Subservice organization is a SOC 2 reporting concept about controls; subprocessor is a privacy-law concept about processing personal data. A cloud host is usually both, but the labels answer different questions.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.