Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Practical SOC 2, HIPAA, and ISO 27001 checklists, a vendor security questionnaire, and an incident response plan template. Drop your email and the download unlocks instantly. No fluff, no sales calls unless you ask.
Gauge how close you are to a SOC 2 audit across access control, policies, technical controls, vendor risk, and evidence.
Download nowThe administrative, technical, and physical safeguards US healthcare buyers and auditors expect from digital health.
Download nowA starting gap checklist against the ISO 27001 ISMS requirements and Annex A control themes.
Download nowAssess a vendor before you rely on them, and pre-answer the SIG/CAIQ/VSA questionnaires your buyers send.
Download nowA lightweight IR plan skeleton: roles, detection, containment, notification, and recovery. What insurers and buyers ask for.
Download nowThese are starting points, not legal or audit advice. When you are ready to actually get there, traztech runs the readiness as a fixed-scope engagement. Book a free readiness call.
Book a free 30-minute readiness call and we will map your real gaps and quote you.
Book a free readiness callDownloading a policy template is the easy half. traztech Workspace keeps the whole set, tracks which control each one satisfies, prompts you for the details only you know, and prints them as PDFs with your approver and review date on the front.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.