Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Vulnerability Management

Continuous scanning is easy. Knowing which findings actually matter, and getting them fixed, is the hard part. We run vulnerability management as a program: scan, triage by real exploitability, and track remediation to closed.

Triage by someone who finds them. five published CVEs and 20+ penetration tests, so exploitability is judged rather than copied from a scanner's severity column.
Get started

A managed program, not a scanner dump

Findings without triage are just noise. We turn scan output into a prioritized, tracked program your team can actually act on.

01

Continuous scanning

Across your cloud, containers, hosts, and dependencies, so new exposure is caught as it appears, not at the next annual test.

02

Triage by real exploitability

We rank findings by whether an attacker could actually use them in your environment, not by CVSS score alone, so your team fixes what matters first.

03

Remediation tracking

Every finding gets an owner, a fix, and a target date, tracked to closed in your portal with severity counts you can show a buyer.

04

Evidence for compliance

Clean reporting that doubles as SOC 2 and ISO 27001 evidence, so the same work serves your audit.

Works well with

If you need someone to own this program end to end, our fractional CISO service can run it, including auditor coordination when findings need to be defended to a reviewer.

Get a handle on your exposure

Tell us about your stack and we will scope a vulnerability program that fits.

Book a Call

Frequently asked questions

How is this different from a penetration test?

A pen test is a point-in-time, human-led attack. Vulnerability management is the ongoing program between tests: continuous scanning, triage, and remediation tracking so exposure does not pile up. Most teams need both.

Do you just resell a scanner?

No. The tooling is the easy part. What you pay for is triage by real exploitability and getting findings actually fixed, led by a published security researcher who knows which issues attackers use.

Does this help with SOC 2 or ISO 27001?

Yes. A documented vulnerability management program with evidence of scanning and remediation is a control auditors look for. We produce reporting that serves as evidence directly.

Buying a penetration test? What to ask every firm, and the retest question most buyers miss: penetration testing companies in Canada.

Which frameworks require vulnerability scanning

Scanning is one of the few controls that nearly every framework names explicitly, and one of the few where the frequency is written down rather than left to your judgement.

FrameworkStatusWhat the requirement says
PCI DSS v4.0Requirements 11.3.1 and 11.3.2 Required Internal vulnerability scans at least every three months and after significant change, plus external scans at least every three months performed by a PCI SSC Approved Scanning Vendor. Both must reach a passing result.
ISO/IEC 27001:2022A.8.8 Required Information about technical vulnerabilities must be obtained, exposure evaluated, and appropriate measures taken. This control is in the Statement of Applicability for essentially every certified organisation.
SOC 2CC7.1 Expected Requires procedures to detect and act on vulnerabilities and configuration changes. Auditors sample scan output, triage records and remediation timelines against your own stated policy.
HIPAA Security Rule45 CFR 164.308(a)(1)(ii)(A) and (B) Expected Risk analysis and risk management require identifying technical vulnerabilities and reducing them to a reasonable level.

On PCI external scans, plainly: we are not an Approved Scanning Vendor, and only an ASV can produce a passing external scan attestation for PCI DSS 11.3.2. We coordinate the ASV, remediate what the scan returns and manage the rescan until it passes. Anyone telling you they can issue that attestation without ASV status is worth checking. The same list of what we cannot sign is on the internal audit page.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Before you go

Want a few notes on this by email?

Short, practical notes on Vulnerability Management. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want it done for you?

Vulnerability Management

Explore Vulnerability Management →