Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Straight-answer guides.

Plain-language answers to the questions founders actually ask about security and compliance: what it costs, which framework you need, and what is really required. No gatekeeping, no invented numbers, just the honest version.

If you would rather skip straight to a plan, browse our compliance services, work through the SOC 2 readiness checklist, or book a free readiness call and we will tell you what applies.

How much does SOC 2 cost?

The real 2026 breakdown: auditor, tooling, and readiness work, plus Type I vs Type II and how to keep the number down.

Read the guide

SOC 2 vs ISO 27001

Which one your startup actually needs, based on who your buyers are, and why doing both is less work than it looks.

Read the guide

What a fractional CISO costs

vCISO pricing in 2026, what drives the number, and how it compares to a $300K-plus full-time hire.

Read the guide

SOC 2 requirements explained

The five Trust Services Criteria, which are mandatory, the controls you need, and the evidence auditors look for.

Read the guide

The Statement of Applicability

Clause 6.1.3 in practice: justifying inclusion and exclusion across all 93 Annex A controls, and the findings a weak SoA attracts.

Read the guide

ISO 27001 internal audit programme

Clause 9.2: programme design, auditor impartiality and competence, sampling, and writing a nonconformity that holds up.

Read the guide

ISO 27001 management review

Clause 9.3: every required input, who has to attend, and minutes that record decisions instead of attendance.

Read the guide

Complementary user entity controls

The CUEC list assigns work to the reader of a SOC 2 report, nobody tests it, and the risk lands on you.

Read the guide

SOC 2 subservice organisations

Carve-out vs inclusive method, the vendor monitoring a carve-out obliges you to run, and what auditors test.

Read the guide

SOC 2 bridge letters

What a gap letter can and cannot assert, who signs it, how long a gap stays credible, and what to do when it is longer.

Read the guide

Running the programme.

Longer guides on how a programme is actually operated: what an auditor asks for, what the record has to contain, and the order the work goes in.

The first 90 days of a compliance programme

What to do in what order once you have been told you need SOC 2 or ISO 27001, and the decisions that are expensive to reverse.

Read the guide

What evidence auditors actually accept

Screenshots versus exports versus system-generated records, population and sample, and the traits that get evidence rejected.

Read the guide

An access review that passes audit

Population definition, the joiner mover leaver feed, what "reviewed" has to mean, privileged and non-human identities, and the failure modes.

Read the guide

An asset inventory that stays true

What is in scope, who owns a record, how it is kept current, and what an auditor samples from it.

Read the guide

A risk assessment that drives work

Methodology, scales that are not arbitrary, risk owners, treatment and acceptance, and the link from a risk to a control to evidence.

Read the guide

Running an incident response tabletop

Scenario selection, injects, facilitation, and what the record has to contain to count as evidence.

Read the guide

BCP and DR testing for small teams

Business impact analysis, RTO and RPO that mean something, what a restore test has to prove, and the evidence.

Read the guide

The vendor DPA and subprocessor register

What has to be on file per vendor, subprocessor disclosure, cross-border transfers, criticality tiering and reassessment cadence.

Read the guide

Running a security questionnaire programme

The answer library, evidence attachment, turnaround, when to push back, CAIQ and SIG, and how a trust centre cuts the volume.

Read the guide

A trust centre: what to publish

Report distribution under NDA, subprocessor lists, policy summaries versus policies, and what a published claim commits you to.

Read the guide

Cyber insurance: what underwriters ask

The application questions, MFA and backup attestations, what a misstatement costs at claim time, and what to have ready at renewal.

Read the guide

Security readiness for diligence

What technical diligence looks at, the artefacts requested, how findings affect terms, and what to fix before the data room opens.

Read the guide

Canadian law, in operator terms.

The statutes and supervisory expectations Canadian buyers cite: what each one actually obliges, who it binds, and what a vendor has to be able to produce.

Prefer the human version?

Get Jacob's take, by email

Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.