Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

How we handle your data

You are trusting a compliance firm with the evidence of your compliance. That is a fair thing to be careful about, so here is exactly how the platform works, in enough detail that you can check it.

Last reviewed: August 2, 2026

Where it lives

Servers in Toronto, Canada, on Akamai Connected Cloud, with Cloudflare in front for edge protection. Your data stays in Canada. The origin only accepts traffic from Cloudflare, so the servers are not reachable directly.

Encryption

TLS in transit, with HSTS so browsers refuse to downgrade. Encryption at rest at the storage layer. Any credential you give an integration is sealed separately with AES-256-GCM, and we cannot display it back to you, only a masked hint.

Getting in

There are no passwords to leak. Sign-in is a one-time link, valid for 15 minutes, usable once, stored only as a hash. Sign-in requests are rate limited per source. Sessions are HttpOnly, Secure, SameSite cookies.

Separation between customers

Every record carries the workspace that owns it, and every query is filtered by it. Identifiers in a URL are checked against your workspace before anything is returned, so changing a number in the address bar returns nothing. We test this by attacking it from one workspace against another.

Who can see what

Four roles. Owners run the workspace. Members do the work but not billing or team changes. Auditors are read-only and limited to assessments, evidence, and policies, enforced on the page rather than by hiding links. Partner administrators reach only their own client workspaces.

Uploaded files

Stored outside anything the web server will serve, renamed to random identifiers, and released only through a handler that checks the file belongs to your workspace. File types are restricted, and anything that could execute in a browser is sent as a download rather than rendered.

When we work in your workspace

During a paid engagement we work inside your records rather than in files of our own. When we do, the screen carries a visible banner naming your organisation, the action is written to our internal audit trail, and anything we draft for you is handed back for you to approve. Your name goes on the approval, not ours.

How long we keep it

For as long as the workspace is in use. A workspace with no sign-in for 23 months gets a warning, and is deleted at 24. Ask for deletion sooner and we remove it. Records tied to invoices or signed contracts are kept longer because tax and contract law require it.

What we are not

We are not SOC 2 audited, and we will not dress this page up to look like we are. There is no certificate behind any of the above. What there is: a platform built by people who assess these controls for a living, a written account of how it works, and a standing offer to answer anything your security team wants to ask before you put data in it.

If you find something wrong with it, tell us at [email protected]. We will not argue with you and we will not threaten anyone who reports a flaw in good faith.

Does this portal land inside your audit?

Does my auditor need to see that this portal is SOC 2 compliant?

Almost always no. The portal is where you prepare for an audit, not part of the system being audited. Your SOC 2 scope is the system that delivers your service to your customers. A readiness tool sits outside that boundary, the same way your ticketing system or your password manager does. What an auditor does expect is that you have assessed us as a vendor, which is a control you own, not a certificate we hold.

Could using this portal hurt my audit?

Only in three situations, and all three are avoidable. If you cannot produce your evidence because it is locked in a tool you cannot export from. If we hold data about you and you have no vendor assessment on file. Or if your evidence has no clear provenance. We export everything on demand, we give you what you need to assess us, and every change is attributed and timestamped.

Are you a subservice organization?

Not for the free workspace. A subservice organization operates controls on your behalf that your own control objectives depend on. Using our software to record your assessment is not that. It can change on a paid engagement: if we are running a control for you, such as ongoing vulnerability management under Traztech Continuous, then that specific control is performed by us and your auditor will either carve it out or ask for assurance over it. We will tell you which applies before you sign, in writing.

Do you hold our production data?

No. The platform holds what you type into it and the evidence files you choose to upload, which are things like policy documents, access review exports, and configuration screenshots. We do not connect to your production systems and we do not process your customers' data.

Are you SOC 2 certified yourselves?

No, and we will not imply otherwise. We are a readiness firm, not an audited service provider, and there is no SOC 2 certificate in any case, only an attestation report. If your procurement process requires an audited vendor, say so early and we will tell you honestly whether we clear that bar.

How do we get our data out?

Every register exports to CSV from its own page, policies download as documents, and uploaded files download as you left them. There is no export request and no waiting period. If you want the account deleted, email [email protected] and it goes.

Subprocessors

Akamai Connected Cloud hosts the servers in Toronto. Cloudflare sits in front as CDN and edge security. Google Workspace carries transactional email. Stripe handles card payments, and we never see or store a card number. That is the whole list for the platform. The privacy policy covers the marketing site as well, including analytics, which the portal itself does not run.

Privacy policy Terms AI policy Ask us something specific