Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Every engagement below has a fixed price, a defined scope, and a stated timeline. You can work out what you need and roughly what it costs without booking anything, and you can put a real number in front of whoever approves your budget.
Most firms only quote after a discovery call, so you cannot compare two without sitting through two sales processes. Here you can budget and get sign-off before you ever book one. If your situation does not fit a fixed scope, we will say so.
| Engagement | Price (CAD) | Time to deliver | What it gets you |
|---|---|---|---|
| Free 30-min Discovery Call | $0 | 30 min | A straight read on where you stand and what it would cost |
| Cloud Cost Audit AWS · GCP · Azure | From $2,000 | 1 week | A costed list of what to change, and what it saves |
| Technical Due Diligence Light | From $4,500 | 5 business days | A diligence-ready technical report your investors can read |
| Penetration Testing & Security Assessment | From $1,000 | Scoped | Findings with severities, plus the retest that proves they are fixed |
| AI/LLM Security Assessment | From $4,000 | 1 week | Where your AI features are exposed, and how to close it |
| SOC 2 in 75 Days | From $3,000 (gap) | 75 days | Audit-ready in 75 days, with the evidence already collected |
| SOC 2 Type I in 10 Weeks | From $2,000 (gap) | 10 weeks | A Type I report to unblock the deal, and a clean run at Type II |
| ISO 27001 Readiness in 16 Weeks | From $3,000 (gap) | 16 weeks | An ISMS that survives Stage 1 and Stage 2 |
| Quebec Law 25 Readiness Sprint New | From $6,000 | 4 weeks | Law 25 obligations met, with a named privacy officer in place |
| Incident Response Tabletop | From $3,000 | 1 day | A tested incident plan, and a team that has run it once |
| Fractional / Virtual CISO | From $3,000/mo | Ongoing | Someone senior accountable for security, without a full-time hire |
| Retainers & ongoing work | From $X,XXX/mo | Ongoing | Continuous compliance, security program, and incident response, scoped to you |
Tell us where you are, what’s on fire, and what you’ve already tried. We’ll tell you whether we’re the right team, point you at a fixed-price engagement if one fits, or refer you out if we’re not. No pitch deck.
According to the FinOps Foundation’s 2026 State of FinOps and Gartner, organizations waste an average of 30 to 32% of their cloud budget on idle resources, oversized instances, and architectural inefficiency. Whichever platform you run (AWS, Google Cloud, Azure, or a mix), we find it, quantify it, and hand you a prioritized remediation list ranked by dollars saved per hour of engineering time.
Full Series A technical due diligence runs $25,000 to $40,000 and takes weeks. Most pre-Series A founders don’t need that. They need a credible 5-day “dipstick” covering architecture, code quality, scalability, and security gaps that a partner would actually flag. That’s what this is.
VCs see this report before the term sheet conversation. Founders use it to pre-empt diligence kill-shots and build a credible remediation plan.
This is not an automated scanner. It is a hands-on, week-long adversarial assessment of your AI system, run by a published security researcher and delivered with one of our global and Canadian testing partners. We threat-model how your LLM, RAG, and agent surfaces are actually wired together, then attack them by hand: prompt injection (direct and indirect), jailbreaks and guardrail bypass, tool and agent abuse, and data exfiltration.
Testing is structured against the OWASP LLM Top 10 so coverage is deliberate and explainable, not a spray of generic checks. You get every finding rated by severity with reproduction steps and concrete remediation guidance your engineers can act on.
We will not sell you more than you need. A small surface gets light-touch work and a price that reflects it. A complex system that matters gets deep, hands-on investigation. You get the depth the situation calls for, not a padded quote.
Web app, network, server, cloud, and API testing, plus vulnerability assessment. When an engagement calls for it, we bring in one of our testing partners for specialist adversarial depth. We work with both Canadian and global firms and put the one that gives you the best value on your engagement, which for Canadian work usually means a local firm priced in CAD. See the full security services.
What you pay us here is a fixed-scope gap analysis. Remediation and audit coordination are scoped as Phase 2, once the gap shows what you need. The CPA auditor fee is separate (prep work vs the audit firm). Type I usually takes 3 to 4 months. We do it in 75 days, for roughly half what Big 4 readiness costs.
What you pay us here is a fixed-scope gap analysis. Remediation and audit coordination are scoped as Phase 2, once the gap shows what you need. The CPA auditor fee is separate. A Type I proves your controls are designed right at a point in time, which is usually what unblocks the deal. About 10 weeks, then Type II runs in parallel. Full playbook: SOC 2 for Canadian SaaS.
What you pay us here is a fixed-scope gap analysis. Remediation and audit coordination are scoped as Phase 2, once the gap shows what you need. The CPA auditor fee is separate. We build the ISMS, Statement of Applicability, risk treatment plan and internal audit, ready for Stage 1 and Stage 2 in about 16 weeks. If you need SOC 2 as well, we scope both so the evidence is built once. Full ISO 27001 guide.
Why it’s hot: All provisions have been in force since September 2024. Data portability is the freshest requirement, with 30-day response windows. Many SMBs and out-of-province SaaS vendors selling into Quebec clients are still non-compliant. Penal sanctions can reach $25M CAD or 4% of global revenue, whichever is higher.
Who buys: Any SaaS or services firm with Quebec users. Section 12.1 specifically requires meaningful disclosure of automated decision-making logic, a frequent gap for AI-powered products.
Cheap insurance the board loves. We facilitate a realistic scenario (ransomware, third-party breach, insider threat, or a custom one tied to your stack), walk your team through detection, containment, comms, and recovery, then deliver an after-action report your insurer and your board can both read.
Executive security leadership without the $300K salary line. Your vCISO owns the security program, answers buyer and bank security questionnaires, sits in on customer security calls, and steers the compliance roadmap. Scoped to what you actually need, from a few hours a week to heavy involvement during an audit or a deal cycle. See the full Fractional CISO service.
The work that has to keep happening after a fixed-scope engagement ends: operating the compliance calendar through a Type II observation window, keeping the evidence register true, owning the security program, and answering the pager. One agreement rather than three stacked retainers. Everything else on this page carries a published price because a fixed scope can hold one; ongoing work cannot honestly be reduced to a single figure, so you get a written scope, a monthly number and a plan of approach after one call. See how that works.
Done-for-you readiness for whatever framework your buyers or regulators ask for. Each starts with a fixed-scope gap analysis; remediation and audit coordination are scoped afterward, and any third-party auditor fee is separate. Every one is a door-opener into an ongoing program.
| Readiness sprint | Price (CAD) | Prepares you for |
|---|---|---|
| ISO 27001 Readiness | From $3,000 (gap) | ISO 27001 certification audit |
| ISO 42001 (AI) Readiness New | From $3,000 (gap) | ISO 42001 AI management system |
| AI Governance | From $3,000 (gap) | ISO 42001 / NIST AI RMF foundation |
| HIPAA Readiness | From $3,000 (gap) | US health-data (PHI) obligations |
| PCI DSS Readiness | From $3,000 (gap) | PCI DSS v4.0.1 assessment |
| NIST CSF Assessment | From $2,500 (gap) | NIST CSF 2.0 posture & roadmap |
| GDPR Readiness | From $3,000 (gap) | EU GDPR obligations |
| PIPEDA Readiness | From $2,500 (gap) | Canadian federal privacy (PIPEDA) |
| EU AI Act Readiness Deadline | From $3,000 (gap) | EU AI Act high-risk obligations |
| Cyber Insurance Readiness | From $2,500 (gap) | Cyber-insurance underwriting controls |
Estimated CAD ranges live on each framework’s cost page (e.g. ISO 27001 cost, HIPAA cost, PCI DSS cost). Browse all services & offers or the framework guides.
Ongoing and project-based security work, each scoped to your environment. Testing and hands-on offensive work bring in one of our global or Canadian testing partners when an engagement calls for it, whichever gives you the best value on the scope.
| Service | Price (CAD) | What it is |
|---|---|---|
| Vulnerability Management | From $1,000/mo | Continuous scanning, triage, and remediation tracking |
| Threat & Risk Assessment (TRA) | From $3,000 | Formal TRA for procurement and vendor reviews |
| Vibe-Coding QA & Review | From $2,000 | Security review and testing of AI-built code |
| Cloud Security Review | From $1,000 | AWS, GCP, and Azure posture and hardening |
| Auditor Management & Advocacy | From $2,000 | We manage the auditor relationship for you |
| Security Questionnaire Completion | From $1,000 | We complete SIG, CAIQ, VSA, and custom questionnaires |
| Trust Center | Included for clients | A public trust page built from your workspace. Free while we are engaged; hosted monthly if you are not a client, ask us |
| Third-Party / Vendor Risk | From $2,500 | Assess and monitor the vendors you rely on |
| AI Vendor Risk Assessment | From $2,000 | Assess third-party AI tools before you adopt them |
All floors are starting points; every engagement is scoped to your environment. Browse all services & offers.
Published ranges from other Canadian firms, attributed. We include these because "what should this cost" is the question everybody asks first, and a page that only quotes its own prices does not answer it. Ranges are what each firm published, not what we would quote.
| Work | Published range | Source |
|---|---|---|
| Penetration test, small web application | C$5,000 to C$12,000 | Stingrai, DeepStrike |
| Penetration test, enterprise scope | C$20,000 to C$50,000+ | DeepStrike |
| Penetration testing, day rate | C$1,000 to C$2,000 per day | DeepStrike |
| Penetration testing as a service, annual | C$40,000 to C$120,000 | Stingrai |
| SOC 2 consulting, boutique | C$15,000 to C$40,000 | Truvo Cyber |
| SOC 2 consulting, full service | C$40,000 to C$85,000 | Truvo Cyber |
| SOC 2 consulting, Big 4 | C$80,000 to C$200,000+ | Truvo Cyber |
Three things these tables never show you.
The audit fee is separate. Every range above is for consulting or testing. The CPA firm or certification body bills you directly, and no readiness quote includes it.
Quotes for identical scope differ enormously. Across four firms quoting one scope on a recent engagement, the highest was 2.1 times the lowest. That is mostly about differing assumptions rather than differing quality. What drives the spread.
Being ready reduces the number. On a recent engagement the audit firm took $11,000 off a five-figure quote once the readiness position was evidenced. How that worked.
Most teams pricing a readiness programme have also been quoted a compliance platform to run it in. That is a separate annual number, and it is usually a large one. You do not need it to work with us.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
The prices above are what we charge. The auditor or certification body bills you separately, and that number varies more than people expect: why two quotes for the same scope come back so far apart, and how we pick and vet the firm.
These are the longer answers: what drives the number, what an auditor or a testing firm charges on top, and what the same work goes for elsewhere in Canada. Written to be useful whether or not you buy from us.
Most security firms sell you hours and tell you the total afterwards. Here the deliverable, the timeline, and the price are all agreed before anything starts.
Defined scope, defined price, defined timeline. You can take it to your finance lead without a discovery call first, and procurement has something concrete to review instead of a statement of work that takes a quarter to negotiate.
By the time an engagement finishes we know your stack, your team, and where you are actually exposed. If you want ongoing help after that, it is grounded in your environment rather than a generic maturity model. If you do not, you still keep the deliverable.
If your situation does not match a fixed scope, we say so on the call and quote it properly. We do not stretch a $4,500 engagement into a $40,000 statement of work, and we will tell you when you do not need us yet.
Not sure which fits? Book the free 30 minutes and we will point you at the right one, or tell you it is not us.
Book a callThe engagements listed with a price have defined scope and fixed pricing, so you know what you are buying. Broader advisory and ongoing work is scoped to your situation. We are clear up front about which is which before any work starts.
No. Every engagement produces a deliverable, and we walk you through what it means for your risk, your roadmap, and the buyers asking you for it. A report with no context is the thing you can already buy elsewhere for less.
Because an hourly meter makes the total unknowable until it is too late to plan around. A fixed scope means you know the deliverable, the timeline, and the cost before you commit. Where work genuinely cannot be fixed-scoped, we scope it openly rather than forcing it into a package.
Yes. Fractional CISO and incident response retainers are ongoing engagements scoped to your needs and cadence. We agree on scope up front and adjust as your requirements change, without locking you in for the sake of it.
Four questions separate a scoped engagement from a package priced before anyone has seen your environment. Ask them of us and of anyone else you are considering. The answers tell you who is carrying the risk of being wrong about the size of the work.
| Ask | Fixed-scope gap assessment | Bundled all-in package |
|---|---|---|
| Do you know the remediation cost before seeing the gaps? | No, and it does not claim to. Phase 1 finds the gaps, Phase 2 is priced from them. | It has to assume one. That assumption was made before anyone looked at your systems. |
| Is the penetration test scoped to my actual environment or to a standard package? | Scoped: application count, user roles, API surface and cloud accounts are counted first. | A set number of tester days, whatever your surface turns out to be. |
| Who is the CPA auditor, and have you worked with them before? | Named before you sign, with a reference call if you want one. The choice stays yours. | Ask. If the answer is vague, you are buying the introduction as well as the work. |
| What happens if the assessment finds more work than the price covers? | You see the findings, then decide. Nothing is committed before you have the number. | Either the price was padded for the worst case, or scope is renegotiated later, when you have a deadline. |
A bundled price is not dishonest by itself, and for narrow, well-defined work it is the right shape. The question is only whether the fixed number spans work whose size nobody knew at quoting time.
Book a call and tell us your situation, deadline, and what you are selling into. For anything listed with a price we can confirm scope quickly. For broader work we scope it and come back with a written proposal. No invented numbers and no pressure.
Everything above is paid work. The Workspace is not: it is free, with no card and no seat limit, and it is where the engagements above are run from.
See what the Workspace does →Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.