Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

EU AI Act Risk Classifier

Work through this short decision flow to see where your AI system likely sits under the EU AI Act (unacceptable, high-risk, limited-risk, or minimal-risk), and the obligations that follow.

Step 1 · Prohibited practices (Article 5)

Does your AI system do any of these?

These practices are banned outright under the EU AI Act. Tick any that apply.

If none apply, leave them all unchecked and continue.

Step 2 · High-risk uses (Annex I & III)

Is your system used in any of these contexts?

These are the regulated high-risk domains. Tick any where your system is used to make or materially influence decisions about people.

Only tick a box if the AI meaningfully affects the outcome, not if it is a trivial helper.

Step 3 · Transparency triggers (Article 50)

Does your system do any of these?

These trigger limited-risk transparency duties even when the system is not high-risk.

Obligations that typically follow
    How this works, and why it is not legal advice. This tool applies the EU AI Act's own tiering logic: prohibited practices are checked first, then high-risk uses, then transparency triggers, and anything left is minimal-risk. Classification in the real Act depends on precise definitions, annex entries, and exceptions that are fact-specific. Obligations phase in on a staggered timeline, amended by Regulation (EU) 2026/1744 in July 2026. Article 50 transparency duties apply from 2 August 2026; stand-alone high-risk obligations from 2 December 2027. Treat this as a directional starting point, not a compliance determination.

    Not ready for a call yet?

    Get the EU AI Act playbook

    A few short notes from Jacob on getting an AI product ready for the EU AI Act without drowning in the annexes. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    EU AI Act Readiness

    We map your AI systems to the Act, confirm your risk tier, and build the compliance evidence you will need.

    Explore EU AI Act Readiness →

    Need to get EU AI Act ready?

    We inventory your AI systems, confirm each one's risk tier, and build the documentation, risk management, and transparency evidence the Act expects, on the phased timeline that applies to you. This pairs well with our ISO 42001 (AI) readiness work, and if the terminology is new, see our AI / LLM Security glossary entry.

    About EU AI Act readiness Book a call

    Want the full picture on EU AI Act?

    This gives you the shape of the problem. The full picture is all 60 obligations of EU AI Act, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free EU AI Act assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    76
    Controls taken from nothing to a passed SOC 2 Type II
    Zero
    Exceptions on that Type II report
    20+
    Penetration testing engagements delivered

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.