Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Due Diligence Readiness Scorecard

Preparing for a raise or screening a target? Answer nineteen questions across six areas and get a red, amber or green rating with the red flags that change a deal.

Who is answering?

Overall rating
 
Not started
By area
Red flags
    Technical due diligence, From $4,500 CAD
    A screen, not a diligence report. Areas are rated green, amber or red from your answers, and some questions are marked as red flags because a gap there tends to change a valuation or a deal timeline. Findings still need to be checked against the code and the systems.

    Questions

    What do investors look at in technical due diligence?

    Whether the architecture will carry the plan, whether the code can be maintained and extended, what the security posture and compliance gaps are, whether the team and process can keep shipping, and how much depends on one or two people. The red flags matter more than the average.

    Does AI-generated code count against a company?

    Not by itself. What matters is whether someone understands and reviews it, whether it is tested, and whether it carries the usual gaps such as missing authorization checks or secrets in the repo. Unreviewed AI-generated code in core paths is a finding; reviewed code is just code.

    Can a startup use this before a raise?

    Yes. Choose the startup mode, answer honestly, and fix or document the red flags before the data room opens. A known issue with a plan reads far better than one an investor finds.

    Is this scorecard free?

    Yes, free and no signup. Your answers stay in your browser.

    Not ready for a call yet?

    Get your scorecard by email

    Your rating and red flags to keep, then a few short notes from Jacob on what technical diligence actually looks at. Unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Technical Due Diligence

    Architecture, code, security and compliance reviewed, with the red flags and what they cost to fix.

    Explore Technical Due Diligence →

    Find the red flags before they find the deal.

    For investors, we review the architecture, code, security posture and compliance gaps of a target and tell you what the red flags cost to fix. For startups, the same review gets you ready before the data room opens. From $4,500 CAD.

    See technical due diligence Book a call

    Want the full picture?

    This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

    Start your free assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.