A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Most teams have an incident response plan nobody has ever run. The first time you find out whether it works should not be the morning it matters.
We facilitate a realistic scenario against your actual stack, walk your people through detection, containment, comms and recovery, and write up where it broke.
You leave with a plan that has actually been run once, a written record for whoever is asking, and a short list of the things that would have gone wrong. It is the cheapest evidence of incident readiness you can buy, and it doubles as SOC 2 and ISO 27001 evidence.
The price above covers the work. It also covers where the work lives, which most buyers are quoted separately as an annual platform subscription.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
The exercise itself runs 3 to 4 hours, as a half day. The after-action report follows within a week, so your team is not held up waiting on the write-up.
The people who would really be involved in a live incident: engineering, an executive who can make the call to disclose or escalate, and whoever owns legal and customer comms. A tabletop with only engineers in it tests the wrong half of the problem, because the hard decisions in a real breach are rarely technical.
Yes. SOC 2 and ISO 27001 both expect incident response to be tested, not just documented, and the after-action report is written so it drops straight into an evidence request as proof the exercise happened and what came out of it.
That is the useful outcome. A tabletop where nothing breaks tells you nothing you did not already believe. Every gap goes into the report in priority order, with a 30-day remediation checklist, so the exercise ends with a plan rather than a scare.
It is a fixed-scope, one-day engagement, from $3,000, with the current price on the pricing page. The after-action report and remediation checklist are part of that, not a separate charge.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Book a free 30-minute call, or send an inquiry. We’ll tell you whether it fits, what it costs, and when we can start.