Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Security Risk Register Builder

Add each risk by asset, threat, likelihood, and impact. We compute the rating on a standard 5×5 matrix, sort by severity, and build a register you can copy straight into your docs. Everything stays in your browser.

Rating = likelihood × impact (1 to 25). Bands: Low 1 to 4 Medium 5 to 9 High 10 to 15 Critical 16 to 25, the standard qualitative approach in ISO 27005 / NIST-style assessments.

#AssetThreat / RiskLikelihoodImpactScoreRating
No risks yet. Add your first risk above to start building the register.

Not ready for a call yet?

Get the risk management playbook

A few short notes from Jacob on turning a risk register into an actual security program. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

Fractional security leadership

A retained security leader to own your risk register, controls, and treatment plan end to end.

Explore Fractional security leadership →

Turn the register into a program

A register lists risks. A fractional security leader owns them, assigns treatment, and closes them, mapped to SOC 2 or ISO 27001 compliance. Led by a published security researcher.

Explore fractional security leadership Book a call

Frequently asked questions

How is the risk rating calculated?

Each risk is scored on a standard 5x5 matrix: likelihood (1 to 5) multiplied by impact (1 to 5) gives a score from 1 to 25. Scores map to bands: 1 to 4 Low, 5 to 9 Medium, 10 to 15 High, and 16 to 25 Critical. This is the common qualitative approach used in ISO 27005 and NIST-style risk assessments.

Is my data sent anywhere?

No. The register is built entirely in your browser. Nothing you type is sent to a server or stored by this tool. Use the copy button to save your register into your own documents.

Is this a full risk assessment?

It is a starting structure, not a complete assessment. A real risk assessment also considers existing controls, residual risk, risk ownership, and treatment decisions, and validates likelihood and impact against your actual environment. This tool gives you a clean, prioritized register to build from.

Is it free?

Yes, the risk register builder is free with no signup required. Add as many risks as you like and copy the result into your own compliance or security documentation.

Want the full picture on your risks?

This gives you the shape of the problem. traztech Workspace carries a real risk register with owners, treatment plans, and review dates, wired to the control assessments that create the risks in the first place. Start free and keep the register somewhere it will actually get looked at.

Open your free Workspace See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.