Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Plain-language answers to the questions founders actually ask about security and compliance: what it costs, which framework you need, and what is really required. No gatekeeping, no invented numbers, just the honest version.
If you would rather skip straight to a plan, browse our compliance services, work through the SOC 2 readiness checklist, or book a free readiness call and we will tell you what applies.
The real 2026 breakdown: auditor, tooling, and readiness work, plus Type I vs Type II and how to keep the number down.
Read the guideWhich one your startup actually needs, based on who your buyers are, and why doing both is less work than it looks.
Read the guidevCISO pricing in 2026, what drives the number, and how it compares to a $300K-plus full-time hire.
Read the guideThe five Trust Services Criteria, which are mandatory, the controls you need, and the evidence auditors look for.
Read the guideClause 6.1.3 in practice: justifying inclusion and exclusion across all 93 Annex A controls, and the findings a weak SoA attracts.
Read the guideClause 9.2: programme design, auditor impartiality and competence, sampling, and writing a nonconformity that holds up.
Read the guideClause 9.3: every required input, who has to attend, and minutes that record decisions instead of attendance.
Read the guideThe CUEC list assigns work to the reader of a SOC 2 report, nobody tests it, and the risk lands on you.
Read the guideCarve-out vs inclusive method, the vendor monitoring a carve-out obliges you to run, and what auditors test.
Read the guideWhat a gap letter can and cannot assert, who signs it, how long a gap stays credible, and what to do when it is longer.
Read the guideLonger guides on how a programme is actually operated: what an auditor asks for, what the record has to contain, and the order the work goes in.
What to do in what order once you have been told you need SOC 2 or ISO 27001, and the decisions that are expensive to reverse.
Read the guideScreenshots versus exports versus system-generated records, population and sample, and the traits that get evidence rejected.
Read the guidePopulation definition, the joiner mover leaver feed, what "reviewed" has to mean, privileged and non-human identities, and the failure modes.
Read the guideWhat is in scope, who owns a record, how it is kept current, and what an auditor samples from it.
Read the guideMethodology, scales that are not arbitrary, risk owners, treatment and acceptance, and the link from a risk to a control to evidence.
Read the guideScenario selection, injects, facilitation, and what the record has to contain to count as evidence.
Read the guideBusiness impact analysis, RTO and RPO that mean something, what a restore test has to prove, and the evidence.
Read the guideWhat has to be on file per vendor, subprocessor disclosure, cross-border transfers, criticality tiering and reassessment cadence.
Read the guideThe answer library, evidence attachment, turnaround, when to push back, CAIQ and SIG, and how a trust centre cuts the volume.
Read the guideReport distribution under NDA, subprocessor lists, policy summaries versus policies, and what a published claim commits you to.
Read the guideThe application questions, MFA and backup attestations, what a misstatement costs at claim time, and what to have ready at renewal.
Read the guideWhat technical diligence looks at, the artefacts requested, how findings affect terms, and what to fix before the data room opens.
Read the guideThe statutes and supervisory expectations Canadian buyers cite: what each one actually obliges, who it binds, and what a vendor has to be able to produce.
Custodian, agent, electronic service provider or health information network provider, the safeguards duty, audit logging, consent directives, and what a hospital review asks for.
Read the guidePIPEDA, Quebec Law 25, Alberta and BC PIPA, PHIPA and the health statutes: the decision logic, the overlaps, and what each changes operationally.
Read the guideThe Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024: who it binds, the cyber and AI requirements, and what flows down to a supplier.
Read the guideInformation managers, the PIA the Alberta Commissioner reviews before you go live, BC residency history, and what a western health buyer asks.
Read the guideWhat the law actually requires, where residency is procurement policy instead, cross border obligations under Law 25 and PIPEDA, and how to answer honestly.
Read the guideSecurity schedules, threat risk assessments, privacy impact assessments, testing evidence, clearances, and what to build before you bid.
Read the guidePrefer the human version?
Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.