Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Rate a third-party vendor's risk from the data they access, the certifications they hold, and how critical they are to your business. The risk tier and recommended due diligence update live as you choose.
The biggest drivers are how sensitive the data they access is, how deeply they integrate with your systems, and how critical they are to operations. A vendor with broad access to customer data and no recognized certification is the classic high-risk case.
Yes. A current SOC 2 Type II or ISO 27001 report is independent evidence that the vendor operates real controls, so it lowers the residual risk. It does not eliminate it, and you should still review the report and any exceptions.
Use it to right-size due diligence. Low-risk vendors may need only a basic review, while high-risk vendors warrant a security questionnaire, evidence review, contractual security terms, and periodic reassessment.
Reassess high-risk vendors at least annually and whenever their access or your relationship changes materially. Lower-risk vendors can be reviewed on a longer cycle.
Yes, it is free with no signup. If you need a full third-party risk program or vendor assessment, our team can help.
Not ready for a call yet?
A few short notes from Jacob on getting audit-ready without months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Third-Party Risk Management
A managed program for vetting and monitoring your vendors.
Explore Third-Party Risk Management →Auditors and enterprise customers will ask how you vet your vendors. We help you stand up third-party risk management as part of your compliance program, backed by auditor management and advocacy when it's time for the audit.
See our security services Book a callThis gives you the shape of the problem. The free compliance workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the workspace.