Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Shadow AI Exposure Check

Answer 10 questions about how AI tools are used across your organisation to see your exposure to unmanaged, unsanctioned AI and the controls you should put in place.

 
Recommended controls

    Not ready for a call yet?

    Get the shadow AI playbook

    A few short notes from Jacob on getting unmanaged AI tool use under control without banning everything. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    Shadow AI Audit

    We discover the AI tools your team is actually using, flag where data is leaking, and give you an enforceable control set.

    Explore Shadow AI Audit →

    Want to find your real shadow AI footprint?

    Our shadow AI audit discovers the AI tools your team is actually using, shows you where company data is leaving through prompts, and gives you an approved-tool list and controls people will actually follow. If AI features are already embedded in your own product, that is a job for our AI / LLM security assessments. If you need someone to own the policy end to end, our fractional CISO service can run it.

    About the shadow AI audit Book a call

    Frequently asked questions

    What is shadow AI?

    Shadow AI is the use of AI tools and assistants by employees without the knowledge, approval, or oversight of security and IT. It is the AI version of shadow IT, and it creates risk when staff paste sensitive data into consumer tools or wire unvetted AI into workflows.

    Why is shadow AI a risk?

    Sensitive data can leave your control through prompts, unvetted tools may have weak security or unclear data-retention terms, and outputs can be wrong or biased without anyone accountable. Because it is unmanaged, you often have no visibility into where company data is going.

    How is the exposure level calculated?

    Each question checks whether a basic control against unmanaged AI use is in place. The more controls you are missing, the higher your exposure. Missing controls are returned as your recommended next steps.

    Is the tool free?

    Yes, it is free with no signup. It exists to help you gauge your shadow AI exposure before deciding whether to run a full audit.

    Want the full picture on ISO 42001?

    This gives you the shape of the problem. The full picture is all 38 Annex A controls and 29 AIMS clauses (4-10) of ISO 42001, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free ISO 42001 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    76
    Controls taken from nothing to a passed SOC 2 Type II
    Zero
    Exceptions on that Type II report
    20+
    Penetration testing engagements delivered

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.