Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Every engagement below has a fixed price, a defined scope, and a stated timeline. You can work out what you need and roughly what it costs without booking anything, and you can put a real number in front of whoever approves your budget.
Most security firms quote after a discovery call, which means you cannot compare two of them without sitting through two sales processes. Published prices let you compare like for like, get internal sign-off in days rather than months, and start with a deliverable instead of an open-ended retainer. If your situation does not fit a fixed scope, we will tell you that on the call rather than stretching one to fit.
| Engagement | Price (CAD) | Time to deliver | What it gets you |
|---|---|---|---|
| Free 30-min Discovery Call | $0 | 30 min | A straight read on where you stand and what it would cost |
| Cloud Cost Audit AWS · GCP · Azure | From $2,000 | 1 week | A costed list of what to change, and what it saves |
| Technical Due Diligence Light | From $4,500 | 5 business days | A diligence-ready technical report your investors can read |
| Penetration Testing & Security Assessment | From $1,000 | Scoped | Findings with severities, plus the retest that proves they are fixed |
| AI/LLM Security Assessment | From $4,000 | 1 week | Where your AI features are exposed, and how to close it |
| SOC 2 in 75 Days | From $3,000 (gap) | 75 days | Audit-ready in 75 days, with the evidence already collected |
| SOC 2 Type I in 10 Weeks | From $2,000 (gap) | 10 weeks | A Type I report to unblock the deal, and a clean run at Type II |
| ISO 27001 Readiness in 16 Weeks | From $3,000 (gap) | 16 weeks | An ISMS that survives Stage 1 and Stage 2 |
| Quebec Law 25 Readiness Sprint New | From $6,000 | 4 weeks | Law 25 obligations met, with a named privacy officer in place |
| Incident Response Tabletop | From $1,000 | 1 day | A tested incident plan, and a team that has run it once |
| Fractional / Virtual CISO | From $3,000/mo | Ongoing | Someone senior accountable for security, without a full-time hire |
Tell us where you are, what’s on fire, and what you’ve already tried. We’ll tell you whether we’re the right team, point you at a fixed-price engagement if one fits, or refer you out if we’re not. No pitch deck.
According to the FinOps Foundation’s 2026 State of FinOps and Gartner, organizations waste an average of 30 to 32% of their cloud budget on idle resources, oversized instances, and architectural inefficiency. Whichever platform you run (AWS, Google Cloud, Azure, or a mix), we find it, quantify it, and hand you a prioritized remediation list ranked by dollars saved per hour of engineering time.
Full Series A technical due diligence runs $25,000 to $40,000 and takes weeks. Most pre-Series A founders don’t need that. They need a credible 5-day “dipstick” covering architecture, code quality, scalability, and security gaps that a partner would actually flag. That’s what this is.
VCs see this report before the term sheet conversation. Founders use it to pre-empt diligence kill-shots and build a credible remediation plan.
This is not an automated scanner. It is a hands-on, week-long adversarial assessment of your AI system, run by a published security researcher and delivered with our partner Lorikeet Security. We threat-model how your LLM, RAG, and agent surfaces are actually wired together, then attack them by hand: prompt injection (direct and indirect), jailbreaks and guardrail bypass, tool and agent abuse, and data exfiltration.
Testing is structured against the OWASP LLM Top 10 so coverage is deliberate and explainable, not a spray of generic checks. You get every finding rated by severity with reproduction steps and concrete remediation guidance your engineers can act on.
We will not sell you more than you need. Every engagement is scoped to the real risk in front of you, and the right expert is put on your case, no matter what. A small surface gets focused, light-touch work and a price that reflects it. A complex system that actually matters gets deep expertise and hands-on investigation. You get the depth the situation calls for, not a padded quote.
Web app, network, server, cloud, and API testing, plus vulnerability assessment. When an engagement calls for it, we bring in our offensive-security partner Lorikeet Security for specialist adversarial depth. See the full security services.
What you pay us here is a fixed-scope gap analysis. Remediation, control implementation, and audit coordination are scoped as Phase 2 once the gap shows what you actually need, and the CPA auditor fee is separate (here is how prep work differs from the audit firm). The industry standard SOC 2 Type 1 timeline is 3 to 4 months, with most automated platforms claiming “90 days” that often slip to 150. We deliver in 75 days with traztech’s control implementation playbook and a vetted CPA partner, bringing in our security partner Lorikeet Security when an engagement calls for it. Pricing undercuts Big 4 readiness engagements by 50% or more.
What you pay us here is a fixed-scope gap analysis. Remediation, control implementation, and audit coordination are scoped as Phase 2 once the gap shows what you actually need, and the CPA auditor fee is separate. When a deal needs evidence quickly, a Type I report proves your controls are designed correctly at a point in time. We get you there in about 10 weeks, then you run the Type II observation window in parallel so you are never paying for two disconnected projects. See the full playbook in SOC 2 for Canadian SaaS.
What you pay us here is a fixed-scope gap analysis. Remediation, control implementation, and audit coordination are scoped as Phase 2 once the gap shows what you actually need, and the CPA auditor fee is separate. We build the information security management system, the Statement of Applicability, the risk treatment plan, and the internal audit, and get you ready for the Stage 1 and Stage 2 certification audits in about 16 weeks. If you also need SOC 2, we scope both so the evidence is built once. See the full ISO 27001 implementation guide.
Why it’s hot: All provisions have been in force since September 2024. Data portability is the freshest requirement, with 30-day response windows. Many SMBs and out-of-province SaaS vendors selling into Quebec clients are still non-compliant. Penal sanctions can reach $25M CAD or 4% of global revenue, whichever is higher.
Who buys: Any SaaS or services firm with Quebec users. Section 12.1 specifically requires meaningful disclosure of automated decision-making logic, a frequent gap for AI-powered products.
Cheap insurance the board loves. We facilitate a realistic scenario (ransomware, third-party breach, insider threat, or a custom one tied to your stack), walk your team through detection, containment, comms, and recovery, then deliver an after-action report your insurer and your board can both read.
Executive security leadership without the $300K salary line. Your vCISO owns the security program, answers buyer and bank security questionnaires, sits in on customer security calls, and steers the compliance roadmap. Scoped to what you actually need, from a few hours a week to heavy involvement during an audit or a deal cycle. See the full Fractional CISO service.
Done-for-you readiness for whatever framework your buyers or regulators ask for. Each starts with a fixed-scope gap analysis; remediation and audit coordination are scoped afterward, and any third-party auditor fee is separate. Every one is a door-opener into an ongoing program.
| Readiness sprint | Price (CAD) | Prepares you for |
|---|---|---|
| ISO 27001 Readiness | From $3,000 (gap) | ISO 27001 certification audit |
| ISO 42001 (AI) Readiness New | From $3,000 (gap) | ISO 42001 AI management system |
| AI Governance | From $3,000 (gap) | ISO 42001 / NIST AI RMF foundation |
| HIPAA Readiness | From $3,000 (gap) | US health-data (PHI) obligations |
| PCI DSS Readiness | From $3,000 (gap) | PCI DSS v4.0.1 assessment |
| NIST CSF Assessment | From $2,500 (gap) | NIST CSF 2.0 posture & roadmap |
| GDPR Readiness | From $3,000 (gap) | EU GDPR obligations |
| PIPEDA Readiness | From $2,500 (gap) | Canadian federal privacy (PIPEDA) |
| CPCSC Level 1 & 2 Readiness | From $3,000 (gap) | Government of Canada defence contracts |
| EU AI Act Readiness Deadline | From $3,000 (gap) | EU AI Act high-risk obligations |
| Cyber Insurance Readiness | From $2,500 (gap) | Cyber-insurance underwriting controls |
Estimated CAD ranges live on each framework’s cost page (e.g. ISO 27001 cost, HIPAA cost, PCI DSS cost). Browse all services & offers or the framework guides.
Ongoing and project-based security work, each scoped to your environment. Testing and hands-on offensive work bring in our partner Lorikeet Security when an engagement calls for it.
| Service | Price (CAD) | What it is |
|---|---|---|
| Vulnerability Management | From $1,000/mo | Continuous scanning, triage, and remediation tracking |
| Threat & Risk Assessment (TRA) | From $3,000 | Formal TRA for procurement and vendor reviews |
| Vibe-Coding QA & Review | From $2,000 | Security review and testing of AI-built code |
| Incident Response Retainer | From $500/mo | Named responders and a contracted SLA |
| Cloud Security Review | From $1,000 | AWS, GCP, and Azure posture and hardening |
| Auditor Management & Advocacy | From $2,000 | We manage the auditor relationship for you |
| Security Questionnaire Completion | From $1,000 | We complete SIG, CAIQ, VSA, and custom questionnaires |
| Trust Center Setup | From $1,500 | A public trust page that speeds buyer diligence |
| Third-Party / Vendor Risk | From $2,500 | Assess and monitor the vendors you rely on |
| AI Vendor Risk Assessment | From $2,000 | Assess third-party AI tools before you adopt them |
All floors are starting points; every engagement is scoped to your environment. Browse all services & offers.
Most security firms sell you hours and tell you the total afterwards. Here the deliverable, the timeline, and the price are all agreed before anything starts.
Defined scope, defined price, defined timeline. You can take it to your finance lead without a discovery call first, and procurement has something concrete to review instead of a statement of work that takes a quarter to negotiate.
By the time an engagement finishes we know your stack, your team, and where you are actually exposed. If you want ongoing help after that, it is grounded in your environment rather than a generic maturity model. If you do not, you still keep the deliverable.
If your situation does not match a fixed scope, we say so on the call and quote it properly. We do not stretch a $4,500 engagement into a $40,000 statement of work, and we will tell you when you do not need us yet.
Not sure which fits? Book the free 30 minutes and we will point you at the right one, or tell you it is not us.
Book a callThe engagements listed with a price have defined scope and fixed pricing, so you know what you are buying. Broader advisory and ongoing work is scoped to your situation. We are clear up front about which is which before any work starts.
No. Every engagement produces a deliverable, and we walk you through what it means for your risk, your roadmap, and the buyers asking you for it. A report with no context is the thing you can already buy elsewhere for less.
Because an hourly meter makes the total unknowable until it is too late to plan around. A fixed scope means you know the deliverable, the timeline, and the cost before you commit. Where work genuinely cannot be fixed-scoped, we scope it openly rather than forcing it into a package.
Yes. Fractional CISO, fractional CTO, and incident response retainers are ongoing engagements scoped to your needs and cadence. We agree on scope up front and adjust as your requirements change, without locking you in for the sake of it.
Book a call and tell us your situation, deadline, and what you are selling into. For anything listed with a price we can confirm scope quickly. For broader work we scope it and come back with a written proposal. No invented numbers and no pressure.