Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Continuous scanning is easy. Knowing which findings actually matter, and getting them fixed, is the hard part. We run vulnerability management as a program: scan, triage by real exploitability, and track remediation to closed.
Findings without triage are just noise. We turn scan output into a prioritized, tracked program your team can actually act on.
Across your cloud, containers, hosts, and dependencies, so new exposure is caught as it appears, not at the next annual test.
We rank findings by whether an attacker could actually use them in your environment, not by CVSS score alone, so your team fixes what matters first.
Every finding gets an owner, a fix, and a target date, tracked to closed in your portal with severity counts you can show a buyer.
Clean reporting that doubles as SOC 2 and ISO 27001 evidence, so the same work serves your audit.
If you need someone to own this program end to end, our fractional CISO service can run it, including auditor coordination when findings need to be defended to a reviewer.
Tell us about your stack and we will scope a vulnerability program that fits.
Book a CallA pen test is a point-in-time, human-led attack. Vulnerability management is the ongoing program between tests: continuous scanning, triage, and remediation tracking so exposure does not pile up. Most teams need both.
No. The tooling is the easy part. What you pay for is triage by real exploitability and getting findings actually fixed, led by a published security researcher who knows which issues attackers use.
Yes. A documented vulnerability management program with evidence of scanning and remediation is a control auditors look for. We produce reporting that serves as evidence directly.
Scanning is one of the few controls that nearly every framework names explicitly, and one of the few where the frequency is written down rather than left to your judgement.
| Framework | Status | What the requirement says |
|---|---|---|
| PCI DSS v4.0Requirements 11.3.1 and 11.3.2 | Required | Internal vulnerability scans at least every three months and after significant change, plus external scans at least every three months performed by a PCI SSC Approved Scanning Vendor. Both must reach a passing result. |
| ISO/IEC 27001:2022A.8.8 | Required | Information about technical vulnerabilities must be obtained, exposure evaluated, and appropriate measures taken. This control is in the Statement of Applicability for essentially every certified organisation. |
| SOC 2CC7.1 | Expected | Requires procedures to detect and act on vulnerabilities and configuration changes. Auditors sample scan output, triage records and remediation timelines against your own stated policy. |
| HIPAA Security Rule45 CFR 164.308(a)(1)(ii)(A) and (B) | Expected | Risk analysis and risk management require identifying technical vulnerabilities and reducing them to a reasonable level. |
On PCI external scans, plainly: we are not an Approved Scanning Vendor, and only an ASV can produce a passing external scan attestation for PCI DSS 11.3.2. We coordinate the ASV, remediate what the scan returns and manage the rescan until it passes. Anyone telling you they can issue that attestation without ASV status is worth checking. The same list of what we cannot sign is on the internal audit page.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
Before you go
Short, practical notes on Vulnerability Management. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.