Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Cloud Security Posture Check

Answer 10 questions on IAM, logging, encryption, network exposure, backups, and secrets. Get a posture score, a band, and your top gaps. Works for AWS, GCP, or Azure.

0 / 100 Answer the questions below

Not ready for a call yet?

Get the cloud security playbook

A few short notes from Jacob on hardening cloud environments without a big platform team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

Cloud Security Assessment

A hands-on review of your actual cloud accounts, IAM, and network exposure with a prioritized remediation plan.

Explore Cloud Security Assessment →

Get a real cloud security assessment

A questionnaire finds the obvious gaps. A hands-on review of your actual accounts, IAM policies, and network exposure, alongside ongoing vulnerability management, finds the rest, led by a published security researcher.

Explore the Cloud Security Assessment Book a call

Frequently asked questions

Does this work for AWS, GCP, and Azure?

Yes. The questions cover cloud security fundamentals that apply across AWS, GCP, and Azure: identity and access management, logging and monitoring, encryption, network exposure, backups, and secrets management. The specific service names differ per provider, but the controls are the same.

How accurate is this posture score?

It is a directional self-assessment based on your answers, useful for spotting the biggest gaps and priorities. It is not a configuration scan or a formal audit. A real cloud security assessment inspects your actual accounts, IAM policies, and network setup, which a questionnaire cannot fully capture.

Is it free?

Yes, the posture check is free and requires no signup. It is meant to give teams a quick, honest read on their cloud security with no obligation.

What should I fix first?

The tool ranks your weakest areas so you can start there. In practice, the highest-impact fixes are usually enforcing MFA and least-privilege IAM, centralizing logging, closing public network exposure, and moving secrets out of code into a managed secret store.

Want the full picture on SOC 2?

This gives you the shape of the problem. The full picture is all 61 criteria of SOC 2, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

Start your free SOC 2 assessment See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.