Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Trust Center Builder

Most security questionnaires ask the same forty things. A public trust page answers them once, in the open, so a reviewer can get what they need without your team writing it out again. Mark what you could publish today and see how far it gets you.

1. Your company

Optional. Only used to title the outline.

2. What could you publish today?

Only tick what is true right now. A trust page that overstates gets found out during diligence, which is worse than having no page.

Diligence answered up front

Tick what you can publish to see your coverage.

--
Nothing selected

Tick items on the left to build your outline.

Publish what is true, and date it. The coverage figure is an estimate of how much of a typical mid-market security review a page like this answers without anyone emailing you. It is a guide, not a guarantee, and a regulated buyer or an enterprise procurement team will still send their own form. Two things matter more than completeness: never imply a certification you do not hold, and put a review date on the page, because a trust page that is visibly two years stale reads worse than no page at all. If you would rather have it built and kept current, that is our Trust Center Setup, and Security Questionnaire Completion covers the forms that still arrive.

Questions

What is a trust center?

A public page that answers the security questions buyers ask, before they ask them. It typically covers your certifications, how you handle data, where it is stored, your subprocessors, and how to report a vulnerability or reach a human about security.

Does a trust page really reduce questionnaires?

It rarely removes them entirely, but it shortens them. A reviewer who can find your encryption, retention, subprocessor and certification answers online tends to send a narrower list, and it moves the conversation forward while your team is asleep.

Should I publish my SOC 2 report on it?

Publish that the report exists, along with its type, scope and period. The report itself is normally shared under NDA rather than posted publicly, so the usual pattern is a request form on the page that routes to whoever handles diligence. If you do not have one yet, SOC 2 in 75 Days is the track we run.

What if I do not have a certification yet?

A trust page still helps. Being clear about what you do today, and honest about what is in progress with a date, is more useful to a reviewer than silence. Do not imply a certification you do not hold, because that surfaces quickly and badly during diligence.

Is this tool free?

Yes, free and no signup. It produces an outline and a coverage estimate, not a hosted page.

Before you go

Want your outline by email?

I send a few short notes on getting through buyer security reviews faster, including what reviewers actually look for. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

Trust Center Setup

We build the page, write the answers, and keep it current as things change.

Explore Trust Center Setup →

Answer it once, in public.

We build the trust page, write the answers so they hold up under review, and handle the questionnaires that still come in.

See Trust Center Setup Book a call

Want the full picture on your vendors?

This gives you the shape of the problem. traztech Workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.

Start your free vendor assessment See what is in the Workspace

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
15+
Penetration testing engagements delivered

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.