Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
How it works

What actually happens
when you hire us.

Every framework page explains what a standard asks for. This one explains what the work involves: the four phases, the evidence you will be asked for, what we do against what you do, and the workspace you run it in. If you are deciding whether to start, this is the page that tells you what you are agreeing to.

Talk through your scope See what it costs

Four phases, and the one everyone wants to skip

The shape is the same whichever framework you are pursuing. What changes is the length of phase three, because that is where the observation window lives.

Phase 1
Assessment

Scope, then situation review

The first decision is the boundary: which systems, which sites, which people. It sounds administrative and it is the single most consequential choice in the programme. An ISMS needs a defined scope and a SOC 2 needs a system description, and both are documents an auditor will hold you to. Get it wrong and you either do work you never needed, or discover in month three that something in production was never inside the boundary you described.

Then the assessment itself: current state against every control in scope, with the gaps written down and ranked. If you are pursuing two frameworks we map them against each other here, because the overlap is where the savings are and you cannot bank them once two separate programmes exist.

  • Audit boundary and system description, written
  • Control-by-control current state
  • Findings, ranked, with what each one blocks
  • Where a single control satisfies more than one framework

We do the assessment, the mapping and the findings. You do one scoping conversation and point us at the systems.

Phase 2
Remediation

Close the gaps, in the order that keeps things moving

The instinct is to work top down by severity. The better first pass is to clear anything blocking evidence collection, because a control that is both unremediated and evidence-producing stays invisible until somebody asks for it. If your access review has no owner and no schedule, that is one finding. If it also means you cannot produce a single completed review when the auditor samples the period, it has quietly consumed your timeline as well.

Policies get written here, but writing policies is the small part. The work is making the control actually run, on a schedule, with an owner, producing something dated.

  • Controls rebuilt where the design will not survive sampling
  • Policies drafted from the 40-template library and fitted to how you work
  • Named owners for every control, which is where most gaps surface
  • Evidence pipelines set up so the control documents itself from here on

We do the design, the drafting and the chasing. You do the decisions only you can make, and approve the policies.

Phase 3
Evidence & audit prep

The document request list, and the auditor conversation

This is where the programme becomes concrete. We issue a document request list covering every artefact needed to evidence your controls. On a recent SOC 2 engagement that ran to 84 items, which is typical rather than unusual.

The number surprises people, so it is worth being blunt about why. An auditor does not accept a policy as evidence that a control operates. They want the artefact the control produced. A policy stating that access is reviewed quarterly evidences nothing; the completed review, dated, with the reviewer named and the resulting changes recorded, evidences the control. One control routinely needs several artefacts.

The audit firm is engaged during this phase rather than after it. Scope, sampling approach and what counts as sufficient evidence are all matters you discuss with them, not instructions you receive. A team that first speaks to its auditor when it believes it is ready has given that conversation away.

  • Document request list issued and worked
  • Every artefact reviewed against what the firm will accept, before they see it
  • Audit firm and, for ISO, the certification body introduced and engaged
  • Weekly cadence so a disagreement surfaces in week three, not in fieldwork

We do the request list, the review, and the auditor relationship. You do the retrieval, with us telling you exactly what will and will not pass.

Phase 4
Audit

Fieldwork, and what we are still doing during it

The audit firm performs its own work and issues its own opinion. We cannot influence that and would not want to, because the independence that stops them helping you is the same thing that makes the report worth handing to a buyer.

What we do during fieldwork is absorb it. Sampling requests come to us, evidence goes back in the form they asked for, and questions get answered without pulling your engineers into a thread they have no context for.

Arriving prepared also changes the number. On one engagement the firm took $11,000 off a five-figure quote once the readiness position was set out and a prep firm was confirmed on the programme. That is not a negotiated discount; it is a smaller estimate because there was less uncertainty to price.

We do the sampling responses and the coordination. You do very little, which is the point.

What an 84-item request list actually contains

Taken from a real SOC 2 document request list. Yours will differ by framework and scope, but the categories hold, and so does the ratio: most items are artefacts a control produced, not documents describing a control.

Governance and structure

  • Entity and legal structure documentation
  • Organisational chart with reporting lines
  • Board or advisory governance records
  • Code of conduct or ethics policy
  • Named signatories for each framework role

People

  • Employee and contractor list with roles, start dates and access levels
  • Confidentiality and NDA agreements, contractors included
  • Background check records for a sample of hires
  • Security awareness training completion

Identity and access

  • Identity provider configuration
  • MFA enrolment and enforcement across all users
  • Complete user access list with roles and permissions
  • RBAC role definitions and assignment matrix
  • Provisioning and deprovisioning procedures
  • Completed access reviews, dated, with reviewer named

Change management

  • A sample of production changes with ticket, approval and test evidence
  • Evidence that developers cannot deploy without review
  • Environment separation

Monitoring and response

  • Incident response plan, and evidence it was tested
  • Alert triage records for the period
  • Any incidents, with the post-incident review
  • Vulnerability scan results and remediation against your stated SLA

Data and vendors

  • Encryption at rest and in transit, with key management
  • Backup evidence and a tested restore
  • Vendor inventory with risk tiering and assessments
  • Signed agreements, DPA or BAA where applicable
  • Privacy policy and privacy impact assessment, finalised rather than draft

If you want to know where you stand before talking to anyone, the auditor evidence request simulator runs the same exercise against your own answers and gives you the gap list.

traztech Workspace, and what you actually see in it

The programme runs in a workspace we do not charge for. 14 frameworks with every control explained in plain English, an evidence register, 40 policy templates, a risk register, vendor questionnaires and readiness scoring. It is the same register we work from, so when we request an artefact it lands against the control it evidences rather than in an email thread. You keep all of it when the engagement ends.

Evidence register
MFA enrolment and enforcement evidence, all usersReceived
RBAC role definitions and assignment matrixReceived
Complete user access list with roles and permissionsRequested
Security policies inventory with version numbersRequested
Framework role signatories, namedNot started

Each row is tied to the controls it evidences, so a single artefact can satisfy several at once and you are not uploading the same document five times. The status is what we work from during phase three, and it is what tells you honestly how far along you are, rather than a percentage that moves when you upload anything at all.

Control detail
Logical access is reviewed periodically
Plain-English explanation of what the control means for your company, what an auditor will sample, and which artefact satisfies it. Written per framework rather than copied from the standard, because the control text in the standard is written for assessors.

That translation layer is a large part of what a first-time candidate is paying for anywhere. If the tool does not do it, a person has to, and that person bills. The rest of the workspace is covered on the traztech Workspace page, and it is free to use whether or not you work with us.

Questions we get before starting

How long does a readiness engagement take?

Our SOC 2 track is 75 days of preparation, and we have hit that window every time we have run it. ISO 27001 typically runs longer because the management system, internal audit and management review have to exist before a certification body will assess you. The binding constraint is usually the observation window for a Type II rather than the control work itself.

What do you need from our team?

Less than most people expect, but not nothing. You need one person who can make decisions about scope, and named owners for the controls we identify. Most of the evidence already exists somewhere in your systems; the work is finding it, judging whether an auditor will accept it, and filling the gaps. We do not ask engineers to fill in compliance spreadsheets.

What is a document request list?

It is the list of artefacts needed to evidence your controls. On a recent SOC 2 engagement it ran to 84 items. The number surprises people because an auditor does not accept a policy as evidence that a control operates; they want the artefact the control produced, and one control frequently needs several.

Do we have to buy compliance software?

No. traztech Workspace is free and holds the control sets, the evidence register, the policy templates and the readiness scoring. You keep it when the engagement ends, which matters at the next audit cycle. If you already run a commercial platform we will work inside it instead.

When does the auditor get involved?

During remediation, not after it. Scope, sampling and what counts as sufficient evidence are all things you discuss with an auditor rather than receive from one. Bringing them in early also means a disagreement about evidence surfaces in week three rather than during fieldwork.

What happens if we fail?

The point of preparation is that the question is settled before anyone is sampling for an answer. Where a control will not pass as designed, we say so and rebuild it, which an audit firm is barred from doing for you by the independence rules that make their opinion worth having.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
15+
Penetration testing engagements delivered
$11k
Taken off one client's audit quote by arriving ready

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.

The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.

Recent engagements

For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Want the evidence checklist by email?

A few short notes on getting through a readiness programme, including what auditors actually accept as evidence. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.