Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Technical Due Diligence

Technical due diligence is the assessment an investor or acquirer runs on a company's technology before a funding round or acquisition. It examines the architecture, code quality, security posture, scalability, and key-person risk to find what could undermine the deal's value. Security and compliance maturity is an increasingly large part of it, because unmanaged risk translates directly into price.

In practice

The reviewer is looking for surprises, and unmanaged security risk is a common one. A clean, documented posture does not just pass the check; it removes a lever the other side would otherwise use on valuation.

This is also where a fractional CISO earns their keep. Having one named person who owns the programme and can speak to it credibly is often worth more in the room than any single control.

// how traztech helps

traztech delivers technical due diligence for investors and founders for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

Technical due diligence lands on a short clock, triggered by a term sheet or a letter of intent. The security portion asks the same questions a careful enterprise buyer would: who owns security, is there an attestation, how is risk managed, and what has testing found. We prepare companies for this as technical due diligence.

Companies that treated security as an afterthought discover it during diligence, at the worst possible moment to fix it. A current SOC 2 or ISO 27001 position, a named owner, and recent testing turn this stage from an interrogation into a document hand-off.

Technical Due Diligence: common questions

What does the security part of technical due diligence cover?

Typically security ownership and leadership, any SOC 2 or ISO 27001 status, vulnerability and penetration testing history, incident response, access control, and how third-party and data risk are managed.

How do we prepare for it?

Have the evidence ready before you need it: a current attestation or a documented readiness position, recent test results, a risk register, and a named security owner who can answer for the programme. Scrambling during diligence signals the opposite of maturity.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.