Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A vulnerability assessment is a systematic review that identifies, classifies, and prioritizes known security weaknesses across systems, usually using automated scanning tools. It produces a broad inventory of issues ranked by severity. Unlike a penetration test, it does not attempt to exploit the weaknesses it finds.
A vulnerability assessment gives you breadth: a prioritized list of missing patches, misconfigurations, and known CVEs across your estate. It is fast, repeatable, and well suited to running on a recurring schedule.
The trade-off is depth. Scanners report potential issues without confirming whether they are truly exploitable in your environment, which produces false positives that a human still has to triage.
traztech delivers vulnerability assessment and remediation for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
A vulnerability assessment is the wide, shallow pass: what is exposed, what is out of date, what is misconfigured. It is what tells you the size of the problem before anybody decides how deep to go.
It becomes a compliance artefact when it runs on a schedule and produces evidence that findings were triaged and remediated within a stated timeframe. A one-off scan with no remediation record evidences very little.
It contributes, but auditors generally want to see the whole cycle: scanning on a defined cadence, triage, remediation inside your stated SLA, and evidence of all three across the observation period.
The assessment is the point-in-time activity. Vulnerability management is the ongoing programme around it, including who triages, who fixes and how you prove the loop closed.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.