Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

AI Governance Readiness Assessment

Rate your AI governance program across twelve themes drawn from ISO/IEC 42001 and the NIST AI RMF (Govern, Map, Measure, Manage) to get a maturity score and your prioritised gaps.

0%
Your priority gaps

    Not ready for a call yet?

    Get the AI governance playbook

    A few short notes from Jacob on building an AI governance program that maps to ISO 42001 and the NIST AI RMF without over-engineering it. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    AI Governance Program

    We stand up your AI governance program against ISO 42001 and the NIST AI RMF, from policy and inventory to monitoring.

    Explore AI Governance Program →

    Want to stand up AI governance properly?

    We build ISO/IEC 42001 readiness programs mapped to the NIST AI RMF: policy, an AI system inventory, risk assessment, human oversight, and ongoing monitoring, sized to a startup. Many of the same controls overlap with SOC 2, so if that is also on your roadmap see our SOC 2 readiness checklist.

    About our AI governance program Book a call

    Frequently asked questions

    What is ISO/IEC 42001?

    ISO/IEC 42001 is the international management-system standard for artificial intelligence. It sets out how to establish, operate, and continually improve an AI management system, covering governance, roles, risk, and controls, much like ISO 27001 does for information security.

    What is the NIST AI RMF?

    The NIST AI Risk Management Framework is a voluntary framework organised around four functions: Govern, Map, Measure, and Manage. It helps organisations identify, assess, and reduce risks across the AI lifecycle in a repeatable way.

    How is the maturity score calculated?

    Each question is rated on a three-level maturity scale, from not started to established. The score is your total divided by the maximum, expressed as a percentage, and any theme rated below established is returned as a prioritised gap.

    Is the tool free?

    Yes, it is free with no signup. It exists to help you see where your AI governance program stands before building it out or pursuing ISO 42001 certification.

    Want the full picture on ISO 42001?

    This gives you the shape of the problem. The full picture is all 38 Annex A controls and 29 AIMS clauses (4-10) of ISO 42001, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free ISO 42001 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    76
    Controls taken from nothing to a passed SOC 2 Type II
    Zero
    Exceptions on that Type II report
    20+
    Penetration testing engagements delivered

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.