Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

AI / LLM Security Risk Assessment

Answer 10 questions about your LLM application, each mapped to a category in the OWASP LLM Top 10, to see your risk score, band, and the specific gaps to fix.

0%
Your open gaps (OWASP LLM Top 10)

    Not ready for a call yet?

    Get the LLM security playbook

    A few short notes from Jacob on securing an LLM app against the OWASP LLM Top 10 without a big AppSec team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    LLM Red Teaming

    We adversarially test your LLM app and hand you a fix list.

    Explore LLM Red Teaming →

    Want your LLM app adversarially tested?

    Our LLM red-teaming engagement probes your app for prompt injection, output-handling flaws, excessive agency, and data leakage, then hands you a prioritized fix list your engineers can act on. If you also need a named security owner, a fractional CISO can run the fix list alongside your broader SOC 2 readiness program.

    About LLM red teaming Book a call

    Frequently asked questions

    What is the OWASP LLM Top 10?

    It is a community-driven list of the most critical security risks for applications built on large language models, covering issues such as prompt injection, sensitive information disclosure, improper output handling, excessive agency, and unbounded consumption. It is the standard starting point for LLM threat modeling.

    How is the risk score calculated?

    Each question maps to one category in the OWASP LLM Top 10 and asks whether you have a control in place. The score is the share of controls you have, and the band reflects how much attack surface is currently unmitigated. Missing controls are returned as your specific gaps.

    Is this a penetration test?

    No. It is a self-assessment to help you understand where your LLM app is exposed before you invest in testing. A real LLM red-teaming engagement adversarially probes your app for these weaknesses and validates real impact.

    Is the tool free?

    Yes, it is free with no signup required. It exists to help you scope the risk in your AI product before deciding whether to bring in help.

    Want the full picture on ISO 42001?

    This gives you the shape of the problem. The full picture is all 38 Annex A controls and 29 AIMS clauses (4-10) of ISO 42001, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free ISO 42001 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.