Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

AI Acceptable Use Policy Generator

Fill in a few details about how your team should use AI, and get a clean, copyable starter AI acceptable use policy. Everything is generated in your browser. Nothing you type is sent anywhere.

The tools employees are allowed to use, ideally on business/enterprise tiers.

Leave blank if you prefer an approve-first model where anything not on the approved list is off-limits.

Your starter AI acceptable use policy

Use this as a starting point, not a final document. This generator produces a baseline AI acceptable use policy from the details you enter, entirely in your browser. It is not legal advice. Review and adapt it to your organisation, contractual commitments, and jurisdiction, and have someone accountable for governance sign off before you publish it. A good AI policy is the first control in a broader program that also covers an AI system inventory, risk assessment, and monitoring.

Not ready for a call yet?

Get the AI policy playbook

A few short notes from Jacob on writing an AI policy people actually follow, plus what to build around it. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

AI Acceptable Use Policy

We tailor a defensible AI acceptable use policy to your business and wire it into an approved-tool list your team will actually follow.

Explore AI Acceptable Use Policy →

Want a policy tailored to your business?

We turn this starter into a defensible AI acceptable use policy for your organisation, wire it into an approved-tool list and controls, and align it to the governance frameworks your customers and auditors expect. If your AI products need deeper testing, pair it with our AI / LLM security assessments.

About our AI policy service Book a call

Want the full picture on ISO 42001?

This gives you the shape of the problem. The full picture is all 38 Annex A controls and 29 AIMS clauses (4-10) of ISO 42001, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

Start your free ISO 42001 assessment See what is in the Workspace

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.