A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Technical due diligence is the assessment an investor or acquirer runs on a company's technology before a funding round or acquisition. It examines the architecture, code quality, security posture, scalability, and key-person risk to find what could undermine the deal's value. Security and compliance maturity is an increasingly large part of it, because unmanaged risk translates directly into price.
The reviewer is looking for surprises, and unmanaged security risk is a common one. A clean, documented posture does not just pass the check; it removes a lever the other side would otherwise use on valuation.
This is also where a fractional CISO earns their keep. Having one named person who owns the programme and can speak to it credibly is often worth more in the room than any single control.
traztech delivers technical due diligence for investors and founders for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
Technical due diligence lands on a short clock, triggered by a term sheet or a letter of intent. The security portion asks the same questions a careful enterprise buyer would: who owns security, is there an attestation, how is risk managed, and what has testing found. We prepare companies for this as technical due diligence.
Companies that treated security as an afterthought discover it during diligence, at the worst possible moment to fix it. A current SOC 2 or ISO 27001 position, a named owner, and recent testing turn this stage from an interrogation into a document hand-off.
Typically security ownership and leadership, any SOC 2 or ISO 27001 status, vulnerability and penetration testing history, incident response, access control, and how third-party and data risk are managed.
Have the evidence ready before you need it: a current attestation or a documented readiness position, recent test results, a risk register, and a named security owner who can answer for the programme. Scrambling during diligence signals the opposite of maturity.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.