Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Most security questionnaires ask the same forty things. A public trust page answers them once, in the open, so a reviewer can get what they need without your team writing it out again. Mark what you could publish today and see how far it gets you.
Optional. Only used to title the outline.
Only tick what is true right now. A trust page that overstates gets found out during diligence, which is worse than having no page.
Tick what you can publish to see your coverage.
Tick items on the left to build your outline.
A public page that answers the security questions buyers ask, before they ask them. It typically covers your certifications, how you handle data, where it is stored, your subprocessors, and how to report a vulnerability or reach a human about security.
It rarely removes them entirely, but it shortens them. A reviewer who can find your encryption, retention, subprocessor and certification answers online tends to send a narrower list, and it moves the conversation forward while your team is asleep.
Publish that the report exists, along with its type, scope and period. The report itself is normally shared under NDA rather than posted publicly, so the usual pattern is a request form on the page that routes to whoever handles diligence. If you do not have one yet, SOC 2 in 75 Days is the track we run.
A trust page still helps. Being clear about what you do today, and honest about what is in progress with a date, is more useful to a reviewer than silence. Do not imply a certification you do not hold, because that surfaces quickly and badly during diligence.
Yes, free and no signup. It produces an outline and a coverage estimate, not a hosted page.
Before you go
I send a few short notes on getting through buyer security reviews faster, including what reviewers actually look for. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Trust Center Setup
We build the page, write the answers, and keep it current as things change.
Explore Trust Center Setup →We build the trust page, write the answers so they hold up under review, and handle the questionnaires that still come in.
See Trust Center Setup Book a callThis gives you the shape of the problem. traztech Workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.
Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.