Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Zero Trust is a security model built on the principle "never trust, always verify." It assumes no user, device, or network is trustworthy by default, so every access request is authenticated, authorized, and continuously validated regardless of where it originates. It replaces the old model of a trusted internal network behind a perimeter.
In a Zero Trust architecture, being inside the corporate network grants nothing on its own. Access decisions hinge on verified identity, device health, and least privilege, evaluated per request.
Zero Trust is a strategy delivered through many controls: strong identity and MFA, micro-segmentation, device posture checks, and continuous monitoring. It is a direction you move toward, not a product you install.
traztech delivers zero-trust architecture rollouts for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
Zero trust arrives in questionnaires more often than in engagements. A buyer asks whether you operate a zero trust architecture and somebody has to answer honestly without either overclaiming or sounding behind.
In practice the useful parts for a growing company are identity-centric access, per-request authorisation, and removing implicit trust from network location. Those are concrete and evidenceable. The term itself is not.
No. It is an architectural approach. Vendors sell components that support it, but no single purchase makes an organisation zero trust.
Describe what you actually do: MFA everywhere, least privilege, per-request authorisation, no implicit trust from being inside a network. Overclaiming here is easy to catch and damages the rest of your answers.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.