A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Pick your frameworks and a start month. You get a 12-month calendar of the recurring activities auditors expect to see evidence of, spread out so they do not all land in the same week.
| Month | Activities |
|---|
Some are written into the framework, such as PCI DSS quarterly scans and yearly training. Most are not: SOC 2 and ISO 27001 leave the frequency to you, and auditors then test that you did what your own policy says. The cadences here are the ones most programmes settle on.
For a SOC 2 Type II or an ISO surveillance audit, a missed control is an exception or a nonconformity, so it is better to set a cadence you will keep than an ambitious one you will not. Record the late run with its date rather than backdating it.
Bunching them into one month before the audit is the most common reason they get done badly. Spreading them also gives the risk assessment time to feed the policy review, and the internal audit time to feed the management review.
This calendar is the work. Continuous compliance is having someone run it with you each month, collect the evidence as it happens and chase what slips, so the audit is a review of a year already documented.
Yes, free and no signup. Your choices stay in your browser.
Not ready for a call yet?
Your calendar and evidence list to keep, then a few short notes from Jacob on keeping a programme running between audits. Unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Want it done for you?
Continuous compliance
We run the calendar with you each month and keep the evidence audit-ready.
Explore Continuous compliance →With continuous compliance we run this calendar with you every month, collect the evidence as each activity happens, and chase what slips before the auditor finds it. From $1,500/mo CAD.
Talk about continuous compliance Book a callThis gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.