Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Compliance Cost Estimator

What does getting to an audit actually cost? Compare three routes side by side: doing it in-house on your own staff hours, buying a compliance automation platform, or engaging a firm. Every assumption is on screen and editable, and the answer is a range, never a single number.

Pick the one your buyer or regulator is actually asking for.

More people means more access reviews, more interviews and wider scope for the same control.

A single managed cloud is far less evidence surface than several clouds plus your own hardware.

With nobody owning the programme, more of the writing and chasing has to come from somewhere.

A committed date does not change the work. It compresses it, which costs more per week, not less overall.

Editable estimate for a senior engineer or founder hour, including benefits and overhead. Set it to 0 to see cash cost only.

Frequently required as evidence, and frequently forgotten when people budget. Scope dependent either way.

Do it yourself
$0
first-year total
    Buy a platform
    $0
    first-year total
      Engage a firm
      $0
      first-year total
        The assumptions behind those numbers
        What this suggests
        What this is not

        This is an indicative planning range, not a quote. The cash lines use the ranges we publish in how much SOC 2 costs, and the effort model follows the same logic as our quoting engine, but neither knows your actual environment. Scope, effort and price get confirmed on a call. The three routes are also not mutually exclusive: most teams that engage a firm still run a platform underneath it, which is why tooling appears in every column.

        Not ready for a call yet?

        Get the compliance playbook

        A few short notes from Jacob on getting audit-ready without months of pain, including where the budget actually goes. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

        From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

        Want it done for you?

        SOC 2 in 75 Days

        Readiness, remediation, and auditor coordination on a fixed fee.

        Explore SOC 2 in 75 Days →

        Want a fixed price instead of a range?

        Bring these numbers to a call. We will scope the work to your actual environment and quote it, so the cost is predictable and your engineers stay on the product. See our pricing for what the firm route looks like here.

        See our pricing Book a free readiness call

        Frequently asked questions

        Why does the do-it-yourself route not come out cheapest?

        Because it prices the hours. Doing it yourself is cheapest on cash out the door, since you only pay the auditor and the tool, but readiness commonly consumes hundreds of hours of founder and senior engineer time, and that time comes off product and revenue. This estimator puts a number on that line instead of leaving it hidden. If you set the internal hourly cost to zero you get the cash-only view.

        Does a compliance platform replace the auditor or the work?

        Neither. A platform such as Vanta or Drata automates evidence collection and control monitoring, which genuinely removes a chunk of manual effort. It does not write your policies, fix your misconfigurations, decide your scope, or issue your report. The report can only come from an independent licensed CPA firm, and someone still has to run the programme that connects the two.

        Where do these ranges come from?

        The cash lines use the ranges traztech publishes: roughly ten to forty thousand dollars for the CPA auditor, seven to twenty-five thousand a year for tooling, four to fifteen thousand for a penetration test, and readiness with us from about three thousand a month. The effort model follows the same logic as our quoting engine: a baseline programme length per framework, adjusted for headcount, cloud footprint, whether anyone owns security today, and whether an audit date is already committed.

        Is this a quote?

        No. It is an indicative planning range built from published figures and your own inputs, and it is deliberately shown as a range rather than a number. Scope, effort and price are confirmed on a call, after we have looked at your actual environment.

        Is the estimator free?

        Yes, free with no signup and no payment. It runs entirely in your browser and nothing you type is sent anywhere unless you choose to give us your email for a copy of the result.

        Want the full picture?

        This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

        Start your free assessment See what is in the Workspace

        No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

        Track record

        Who is actually doing the work

        5
        Published CVEs, including a CVSS 9.1
        76
        Controls taken from nothing to a passed SOC 2 Type II
        Zero
        Exceptions on that Type II report
        20+
        Penetration testing engagements delivered

        Published vulnerability research

        Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

        A SOC 2 Type II built from nothing

        At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.