A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Reselling security and compliance work to your clients? Enter what you charge and how many a year. See your margin per engagement and your annual gross profit at your wholesale discount.
| Service | Our list | You pay | You charge | Per year | Margin |
|---|
Partners buy at a percentage off our list price, agreed in the partner terms. You set your own client price, so your margin is the difference between what you charge and what you pay us.
Yes. Engagements can be delivered under your name, co-branded, or by us as your named subcontractor, and the client relationship stays with you.
Most partners start with one request, often a SOC 2 or a penetration test, and then find the same clients need the next thing. Modelling the mix shows whether security services are a side line or a real revenue stream for you.
They are our published starting prices. A larger scope is quoted higher, and the discount applies to the quoted price, so your margin in dollars grows with the engagement.
Yes, free and no signup. Your figures stay in your browser.
Not ready for a call yet?
Your figures to keep, then a few short notes from Jacob on adding security and compliance to an MSP practice. Unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Want it done for you?
MSP and consulting overflow
SOC 2, ISO 27001, penetration testing and vCISO delivery for your clients, white-labelled or co-delivered.
Explore MSP and consulting overflow →We deliver SOC 2, ISO 27001, penetration testing and vCISO work for your clients, white-labelled or co-delivered, and the client relationship stays yours. Tell us the scope and we will confirm partner terms.
See MSP overflow Book a callThis gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.