Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Trust Center

A Trust Center is a public web page where a company publishes its security and compliance posture so buyers can self-serve. It typically lists certifications and reports, subprocessors, data-handling practices, and a security contact, often with gated access to the SOC 2 report under NDA. The point is to answer common security questions before a buyer sends a questionnaire.

In practice

A Trust Center works best when it is honest and current rather than aspirational. Listing a certification you are still pursuing, or a subprocessor list that is out of date, is the kind of thing a sharp reviewer catches and it damages the rest of your answers.

It pairs naturally with a maintained answer library and a named security owner. The page deflects the routine questions; the owner handles the ones that remain, which turns a recurring fire drill into a predictable task.

// how traztech helps

traztech delivers trust centre setup that answers buyers up front for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A Trust Center usually gets built after the fourth or fifth security questionnaire, when a team realises it is answering the same questions over and over. Publishing the answers once, in one place, is the cheapest way to shorten that part of the sales cycle. We handle this as a trust centre setup.

The judgement call is what to expose publicly and what to gate. Certifications, a subprocessor list and a security contact can be open; the report itself and detailed architecture usually sit behind an NDA request. Our own Trust Center shows the shape of it.

Trust Center: common questions

Does a Trust Center replace security questionnaires?

Not entirely, but it removes a large share of them. A good one answers the common questions up front, so reviewers either stop asking or send a much shorter list.

What should a Trust Center include?

At a minimum: current certifications or reports, a subprocessor list, how you handle and locate data, your security contact, and a way to request gated documents under NDA.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.