Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

AI Governance Readiness Assessment

Rate your AI governance program across twelve themes drawn from ISO/IEC 42001 and the NIST AI RMF (Govern, Map, Measure, Manage) to get a maturity score and your prioritised gaps.

0%
Your priority gaps

    Not ready for a call yet?

    Get the AI governance playbook

    A few short notes from Jacob on building an AI governance program that maps to ISO 42001 and the NIST AI RMF without over-engineering it. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    AI Governance Program

    We stand up your AI governance program against ISO 42001 and the NIST AI RMF, from policy and inventory to monitoring.

    Explore AI Governance Program →

    Want to stand up AI governance properly?

    We build ISO/IEC 42001 readiness programs mapped to the NIST AI RMF: policy, an AI system inventory, risk assessment, human oversight, and ongoing monitoring, sized to a startup. Many of the same controls overlap with SOC 2, so if that is also on your roadmap see our SOC 2 readiness checklist.

    About our AI governance program Book a call

    Frequently asked questions

    What is ISO/IEC 42001?

    ISO/IEC 42001 is the international management-system standard for artificial intelligence. It sets out how to establish, operate, and continually improve an AI management system, covering governance, roles, risk, and controls, much like ISO 27001 does for information security.

    What is the NIST AI RMF?

    The NIST AI Risk Management Framework is a voluntary framework organised around four functions: Govern, Map, Measure, and Manage. It helps organisations identify, assess, and reduce risks across the AI lifecycle in a repeatable way.

    How is the maturity score calculated?

    Each question is rated on a three-level maturity scale, from not started to established. The score is your total divided by the maximum, expressed as a percentage, and any theme rated below established is returned as a prioritised gap.

    Is the tool free?

    Yes, it is free with no signup. It exists to help you see where your AI governance program stands before building it out or pursuing ISO 42001 certification.

    Want the full picture on ISO 42001?

    This gives you the shape of the problem. The full picture is all 38 Annex A controls and 29 AIMS clauses (4-10) of ISO 42001, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free ISO 42001 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.