Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Most security questionnaires ask the same forty things. A public trust page answers them once, in the open, so a reviewer can get what they need without your team writing it out again. Mark what you could publish today and see how far it gets you.
Optional. Only used to title the outline.
Only tick what is true right now. A trust page that overstates gets found out during diligence, which is worse than having no page.
Tick what you can publish to see your coverage.
Tick items on the left to build your outline.
A public page that answers the security questions buyers ask, before they ask them. It typically covers your certifications, how you handle data, where it is stored, your subprocessors, and how to report a vulnerability or reach a human about security.
It rarely removes them entirely, but it shortens them. A reviewer who can find your encryption, retention, subprocessor and certification answers online tends to send a narrower list, and it moves the conversation forward while your team is asleep.
Publish that the report exists, along with its type, scope and period. The report itself is normally shared under NDA rather than posted publicly, so the usual pattern is a request form on the page that routes to whoever handles diligence. If you do not have one yet, SOC 2 in 75 Days is the track we run.
A trust page still helps. Being clear about what you do today, and honest about what is in progress with a date, is more useful to a reviewer than silence. Do not imply a certification you do not hold, because that surfaces quickly and badly during diligence.
Yes, free and no signup. It produces an outline and a coverage estimate, not a hosted page.
Before you go
I send a few short notes on getting through buyer security reviews faster, including what reviewers actually look for. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.
Want it done for you?
Trust Center
Built from your compliance workspace and kept current automatically. Included free for clients on a live engagement; hosted for a monthly fee if you are not a client.
Explore Trust Center →We build the trust page, write the answers so they hold up under review, and handle the questionnaires that still come in.
See Trust Center Setup Book a callThis gives you the shape of the problem. traztech Workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.
No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.