A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →No framework yet? Answer 24 questions across ten areas and see your scorecard by NIST CSF 2.0 function, your priority gaps, and a sensible next step.
Answer for how things are today across the whole company, not the best-run team.
No. Most companies start without one. A baseline of the basics tells you where you stand, and it makes choosing between SOC 2, ISO 27001 or CyberSecure Canada later a much easier decision, because the gaps are already known.
The questions are a short, plain-language selection based loosely on the CIS Controls v8.1 Implementation Group 1 safeguards, rolled up to the six NIST Cybersecurity Framework 2.0 functions: Govern, Identify, Protect, Detect, Respond and Recover.
This is a self-assessment that takes a few minutes. The review checks the same areas against a fixed control set with interviews and evidence, and ends with ranked findings, a risk register and a roadmap.
Yes, free and no signup. Your answers stay in your browser.
Not ready for a call yet?
Your scorecard and priority gaps to keep, then a few short notes from Jacob on building a security programme in the right order. Unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Want it done for you?
Enterprise Security Review
Your whole programme reviewed against a fixed control set, with a risk-ranked roadmap.
Explore Enterprise Security Review →An Enterprise Security Review checks these areas against a fixed control set based on CIS Controls v8.1, with interviews and evidence, and ends with a scorecard, ranked findings and a roadmap. From $7,500 CAD.
See the Enterprise Security Review Book a callThis gives you the shape of the problem. The full picture is all 106 subcategories of NIST CSF 2.0, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.