Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Productized engagements Fixed price · Fixed scope

Know the price
before you call us.

Every engagement below has a fixed price, a defined scope, and a stated timeline. You can work out what you need and roughly what it costs without booking anything, and you can put a real number in front of whoever approves your budget.

Why we publish prices

Most firms only quote after a discovery call, so you cannot compare two without sitting through two sales processes. Here you can budget and get sign-off before you ever book one. If your situation does not fit a fixed scope, we will say so.

Seven ways to start

EngagementPrice (CAD)Time to deliverWhat it gets you
Free 30-min Discovery Call$030 minA straight read on where you stand and what it would cost
Cloud Cost Audit AWS · GCP · AzureFrom $2,0001 weekA costed list of what to change, and what it saves
Technical Due Diligence LightFrom $4,5005 business daysA diligence-ready technical report your investors can read
Penetration Testing & Security AssessmentFrom $1,000ScopedFindings with severities, plus the retest that proves they are fixed
AI/LLM Security AssessmentFrom $4,0001 weekWhere your AI features are exposed, and how to close it
SOC 2 in 75 DaysFrom $3,000 (gap)75 daysAudit-ready in 75 days, with the evidence already collected
SOC 2 Type I in 10 WeeksFrom $2,000 (gap)10 weeksA Type I report to unblock the deal, and a clean run at Type II
ISO 27001 Readiness in 16 WeeksFrom $3,000 (gap)16 weeksAn ISMS that survives Stage 1 and Stage 2
Quebec Law 25 Readiness Sprint NewFrom $6,0004 weeksLaw 25 obligations met, with a named privacy officer in place
Incident Response TabletopFrom $3,0001 dayA tested incident plan, and a team that has run it once
Fractional / Virtual CISOFrom $3,000/moOngoingSomeone senior accountable for security, without a full-time hire
Retainers & ongoing workFrom $X,XXX/moOngoingContinuous compliance, security program, and incident response, scoped to you

Free 30-Minute Discovery Call

No commitmentFixed scope
$030 minutes
FormatVideo call
OutcomeHonest read on fit
Next stepScoped proposal or referral out

Tell us where you are, what’s on fire, and what you’ve already tried. We’ll tell you whether we’re the right team, point you at a fixed-price engagement if one fits, or refer you out if we’re not. No pitch deck.

Cloud Cost Audit - AWS, GCP, Azure

ProductizedROI in month 1
From $2,000CAD · 1 week
Avg. cloud waste~30 to 32%
Time to deliver5 business days
Engagement modelRead-only access + readout

According to the FinOps Foundation’s 2026 State of FinOps and Gartner, organizations waste an average of 30 to 32% of their cloud budget on idle resources, oversized instances, and architectural inefficiency. Whichever platform you run (AWS, Google Cloud, Azure, or a mix), we find it, quantify it, and hand you a prioritized remediation list ranked by dollars saved per hour of engineering time.

Deliverables
  • Billing & usage export ingestion (AWS CUR, GCP Billing export, or Azure Cost Management) and tag-hygiene review
  • Top-20 waste findings with annualized $ impact
  • Commitment modelling: Reserved Instances / Savings Plans (AWS), Committed Use Discounts (GCP), Reservations (Azure)
  • Right-sizing across compute, managed databases, storage, idle resources, and data egress
  • 30 / 60 / 90-day remediation roadmap
  • Executive readout deck

Technical Due Diligence Light

Pre-Series AVC-ready
From $4,500CAD · 5 business days
ScopeArchitecture & risk
Compares toFull TDD: $25k to $40k
AudienceVC partners & founders

Full Series A technical due diligence runs $25,000 to $40,000 and takes weeks. Most pre-Series A founders don’t need that. They need a credible 5-day “dipstick” covering architecture, code quality, scalability, and security gaps that a partner would actually flag. That’s what this is.

VCs see this report before the term sheet conversation. Founders use it to pre-empt diligence kill-shots and build a credible remediation plan.

Deliverables
  • Architecture review and dependency map
  • Code quality and test coverage assessment (read-only)
  • Scalability and reliability red flags
  • Security and compliance gap snapshot
  • Team structure and bus-factor assessment
  • VC-formatted executive summary + technical appendix

SOC 2 Type I in 10 Weeks

Point-in-time proof, fast
From $2,000gap analysis
TypeSOC 2 Type I
Time to deliver~10 weeks
Best whenA buyer needs proof now

What you pay us here is a fixed-scope gap analysis. Remediation and audit coordination are scoped as Phase 2, once the gap shows what you need. The CPA auditor fee is separate. A Type I proves your controls are designed right at a point in time, which is usually what unblocks the deal. About 10 weeks, then Type II runs in parallel. Full playbook: SOC 2 for Canadian SaaS.

Deliverables
  • Trust Services Criteria scoping and gap assessment
  • Policies, procedures, and evidence repository
  • Control implementation across IAM, change management, vendor risk, and IR
  • Auditor introduction and audit coordination
  • Audit-ready evidence package for the CPA firm's Type I attestation report

ISO 27001 Readiness in 16 Weeks

Global standard
From $3,000gap analysis
StandardISO/IEC 27001
Time to deliver~16 weeks to Stage 1
Best whenYou sell globally or into Europe

What you pay us here is a fixed-scope gap analysis. Remediation and audit coordination are scoped as Phase 2, once the gap shows what you need. The CPA auditor fee is separate. We build the ISMS, Statement of Applicability, risk treatment plan and internal audit, ready for Stage 1 and Stage 2 in about 16 weeks. If you need SOC 2 as well, we scope both so the evidence is built once. Full ISO 27001 guide.

Deliverables
  • ISMS scope and Statement of Applicability
  • Risk assessment and risk treatment plan
  • Annex A control implementation
  • Internal audit and management review
  • Registrar introduction and Stage 1 and Stage 2 coordination

Incident Response Tabletop

Board-friendlyInsurance-ready
From $3,000CAD · 1 day
FormatHalf-day facilitated exercise
ParticipantsExec, eng, legal, comms
OutputAfter-action report

Cheap insurance the board loves. We facilitate a realistic scenario (ransomware, third-party breach, insider threat, or a custom one tied to your stack), walk your team through detection, containment, comms, and recovery, then deliver an after-action report your insurer and your board can both read.

Deliverables
  • Custom scenario tied to your threat model
  • Facilitated 3 to 4 hour exercise
  • Real-time injects and decision points
  • After-action report with prioritized gaps
  • 30-day remediation checklist

Fractional / Virtual CISO

Month-to-monthUnblocks enterprise deals
From $3,000CAD · per month
ModelFractional, scoped to need
OwnsYour security program
Led byA published security researcher

Executive security leadership without the $300K salary line. Your vCISO owns the security program, answers buyer and bank security questionnaires, sits in on customer security calls, and steers the compliance roadmap. Scoped to what you actually need, from a few hours a week to heavy involvement during an audit or a deal cycle. See the full Fractional CISO service.

Deliverables
  • Security strategy and 12-month roadmap
  • Security questionnaire and buyer-review response
  • Policy, risk register, and vendor-risk management
  • Board and investor security reporting
  • Compliance oversight across SOC 2, ISO 27001, and more

Retainers & ongoing work

MonthlyTooling included
From $X,XXXCAD · per month, scoped to you
CoversContinuous compliance, security program, IR
PricedAfter one scoping call
Includestraztech Workspace

The work that has to keep happening after a fixed-scope engagement ends: operating the compliance calendar through a Type II observation window, keeping the evidence register true, owning the security program, and answering the pager. One agreement rather than three stacked retainers. Everything else on this page carries a published price because a fixed scope can hold one; ongoing work cannot honestly be reduced to a single figure, so you get a written scope, a monthly number and a plan of approach after one call. See how that works.

Deliverables
  • Access reviews, scans, training, tests, and policy reviews run on cadence with the evidence dated
  • Security program ownership: risk register, roadmap, board reporting, questionnaires
  • Incident response: incident command, containment, postmortem, disclosure, tabletops
  • The auditor handled at the next cycle, with sampling agreed before fieldwork
  • traztech Workspace included, or we work in the tooling you already run

Compliance & AI readiness sprints

Done-for-you readiness for whatever framework your buyers or regulators ask for. Each starts with a fixed-scope gap analysis; remediation and audit coordination are scoped afterward, and any third-party auditor fee is separate. Every one is a door-opener into an ongoing program.

Readiness sprintPrice (CAD)Prepares you for
ISO 27001 ReadinessFrom $3,000 (gap)ISO 27001 certification audit
ISO 42001 (AI) Readiness NewFrom $3,000 (gap)ISO 42001 AI management system
AI GovernanceFrom $3,000 (gap)ISO 42001 / NIST AI RMF foundation
HIPAA ReadinessFrom $3,000 (gap)US health-data (PHI) obligations
PCI DSS ReadinessFrom $3,000 (gap)PCI DSS v4.0.1 assessment
NIST CSF AssessmentFrom $2,500 (gap)NIST CSF 2.0 posture & roadmap
GDPR ReadinessFrom $3,000 (gap)EU GDPR obligations
PIPEDA ReadinessFrom $2,500 (gap)Canadian federal privacy (PIPEDA)
EU AI Act Readiness DeadlineFrom $3,000 (gap)EU AI Act high-risk obligations
Cyber Insurance ReadinessFrom $2,500 (gap)Cyber-insurance underwriting controls

Estimated CAD ranges live on each framework’s cost page (e.g. ISO 27001 cost, HIPAA cost, PCI DSS cost). Browse all services & offers or the framework guides.

Security & advisory services

Ongoing and project-based security work, each scoped to your environment. Testing and hands-on offensive work bring in one of our global or Canadian testing partners when an engagement calls for it, whichever gives you the best value on the scope.

ServicePrice (CAD)What it is
Vulnerability ManagementFrom $1,000/moContinuous scanning, triage, and remediation tracking
Threat & Risk Assessment (TRA)From $3,000Formal TRA for procurement and vendor reviews
Vibe-Coding QA & ReviewFrom $2,000Security review and testing of AI-built code
Cloud Security ReviewFrom $1,000AWS, GCP, and Azure posture and hardening
Auditor Management & AdvocacyFrom $2,000We manage the auditor relationship for you
Security Questionnaire CompletionFrom $1,000We complete SIG, CAIQ, VSA, and custom questionnaires
Trust CenterIncluded for clientsA public trust page built from your workspace. Free while we are engaged; hosted monthly if you are not a client, ask us
Third-Party / Vendor RiskFrom $2,500Assess and monitor the vendors you rely on
AI Vendor Risk AssessmentFrom $2,000Assess third-party AI tools before you adopt them

All floors are starting points; every engagement is scoped to your environment. Browse all services & offers.

What the rest of the market charges

Published ranges from other Canadian firms, attributed. We include these because "what should this cost" is the question everybody asks first, and a page that only quotes its own prices does not answer it. Ranges are what each firm published, not what we would quote.

WorkPublished rangeSource
Penetration test, small web applicationC$5,000 to C$12,000Stingrai, DeepStrike
Penetration test, enterprise scopeC$20,000 to C$50,000+DeepStrike
Penetration testing, day rateC$1,000 to C$2,000 per dayDeepStrike
Penetration testing as a service, annualC$40,000 to C$120,000Stingrai
SOC 2 consulting, boutiqueC$15,000 to C$40,000Truvo Cyber
SOC 2 consulting, full serviceC$40,000 to C$85,000Truvo Cyber
SOC 2 consulting, Big 4C$80,000 to C$200,000+Truvo Cyber

Three things these tables never show you.

The audit fee is separate. Every range above is for consulting or testing. The CPA firm or certification body bills you directly, and no readiness quote includes it.

Quotes for identical scope differ enormously. Across four firms quoting one scope on a recent engagement, the highest was 2.1 times the lowest. That is mostly about differing assumptions rather than differing quality. What drives the spread.

Being ready reduces the number. On a recent engagement the audit firm took $11,000 off a five-figure quote once the readiness position was evidenced. How that worked.

The line item that is not on this page

Most teams pricing a readiness programme have also been quoted a compliance platform to run it in. That is a separate annual number, and it is usually a large one. You do not need it to work with us.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote $11,000 off a five-figure quote on one engagement, for a documented readiness position Nothing. The audit firm prices your readiness, not your tooling

Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.

What this work costs, in detail

The prices above are what we charge. The auditor or certification body bills you separately, and that number varies more than people expect: why two quotes for the same scope come back so far apart, and how we pick and vet the firm.

These are the longer answers: what drives the number, what an auditor or a testing firm charges on top, and what the same work goes for elsewhere in Canada. Written to be useful whether or not you buy from us.

What you are actually buying

Most security firms sell you hours and tell you the total afterwards. Here the deliverable, the timeline, and the price are all agreed before anything starts.

01

You know the number before you commit

Defined scope, defined price, defined timeline. You can take it to your finance lead without a discovery call first, and procurement has something concrete to review instead of a statement of work that takes a quarter to negotiate.

02

The advice comes from having done the work

By the time an engagement finishes we know your stack, your team, and where you are actually exposed. If you want ongoing help after that, it is grounded in your environment rather than a generic maturity model. If you do not, you still keep the deliverable.

03

We will tell you when it does not fit

If your situation does not match a fixed scope, we say so on the call and quote it properly. We do not stretch a $4,500 engagement into a $40,000 statement of work, and we will tell you when you do not need us yet.

Pick one, or start with a call

Not sure which fits? Book the free 30 minutes and we will point you at the right one, or tell you it is not us.

Book a call

Frequently asked questions

Are your prices fixed or do they change per project?

The engagements listed with a price have defined scope and fixed pricing, so you know what you are buying. Broader advisory and ongoing work is scoped to your situation. We are clear up front about which is which before any work starts.

Do I just get a report at the end?

No. Every engagement produces a deliverable, and we walk you through what it means for your risk, your roadmap, and the buyers asking you for it. A report with no context is the thing you can already buy elsewhere for less.

Why fixed prices instead of hourly consulting?

Because an hourly meter makes the total unknowable until it is too late to plan around. A fixed scope means you know the deliverable, the timeline, and the cost before you commit. Where work genuinely cannot be fixed-scoped, we scope it openly rather than forcing it into a package.

Do you offer ongoing or retainer pricing?

Yes. Fractional CISO and incident response retainers are ongoing engagements scoped to your needs and cadence. We agree on scope up front and adjust as your requirements change, without locking you in for the sake of it.

What should I ask any readiness partner before signing?

Four questions separate a scoped engagement from a package priced before anyone has seen your environment. Ask them of us and of anyone else you are considering. The answers tell you who is carrying the risk of being wrong about the size of the work.

AskFixed-scope gap assessmentBundled all-in package
Do you know the remediation cost before seeing the gaps? No, and it does not claim to. Phase 1 finds the gaps, Phase 2 is priced from them. It has to assume one. That assumption was made before anyone looked at your systems.
Is the penetration test scoped to my actual environment or to a standard package? Scoped: application count, user roles, API surface and cloud accounts are counted first. A set number of tester days, whatever your surface turns out to be.
Who is the CPA auditor, and have you worked with them before? Named before you sign, with a reference call if you want one. The choice stays yours. Ask. If the answer is vague, you are buying the introduction as well as the work.
What happens if the assessment finds more work than the price covers? You see the findings, then decide. Nothing is committed before you have the number. Either the price was padded for the worst case, or scope is renegotiated later, when you have a deadline.

A bundled price is not dishonest by itself, and for narrow, well-defined work it is the right shape. The question is only whether the fixed number spans work whose size nobody knew at quoting time.

How do I get an exact quote?

Book a call and tell us your situation, deadline, and what you are selling into. For anything listed with a price we can confirm scope quickly. For broader work we scope it and come back with a written proposal. No invented numbers and no pressure.

Everything above is paid work. The Workspace is not: it is free, with no card and no seat limit, and it is where the engagements above are run from.

See what the Workspace does →

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered
$11k
Taken off one client's audit quote by arriving ready

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.