Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Startup Security Score

Check off the security practices you have in place and see where your startup stands. Each unchecked item comes with a specific recommendation. Want a second opinion once you have the basics covered? Our Fractional CISO service and penetration testing and security services pick up where this checklist leaves off.

0 / 100 Check some items below

Not ready for a call yet?

Get the security playbook

A few short notes from Jacob on locking down your startup without a big security team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

CISO-as-a-Service

Ongoing security leadership without a full-time hire.

Explore CISO-as-a-Service →

Get a free security assessment

Our security engineers will do a deep review of your infrastructure, policies, and code. No cost, no commitment. Just actionable findings.

Get a free security assessment

Frequently asked questions

How accurate is the startup security score?

It is a directional snapshot based on your answers, useful for spotting obvious gaps and priorities. It is not a penetration test or a formal audit. A real assessment looks at your actual configuration and code, which a questionnaire cannot fully capture.

Is it free?

Yes, the score is free and requires no payment. It is meant to give founders a quick, honest read on their security posture with no obligation to work with us.

What does the score actually measure?

It covers common startup security fundamentals: access control, MFA, logging, vendor risk, data handling, and basic policy. These are the areas enterprise buyers and auditors ask about first, so weak spots here tend to block deals and compliance.

What should I do with a low score?

Treat it as a prioritized to-do list. the fastest wins are usually access control and MFA, logging, and written policies. If you want help, we can run a proper assessment and remediation, and our founder, a published security researcher, leads that work. Book a call to go deeper.

Want the full picture on SOC 2?

This gives you the shape of the problem. The full picture is all 61 SOC 2 criteria, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

Start your free SOC 2 assessment See what is in the Workspace

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.