Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Vibe-Coded App Launch Checklist

AI coding tools get an app working fast and leave the same gaps behind. Answer twelve questions and get a launch risk score with the fixes to make first.

Twelve things to check before launch

For apps built with AI coding tools. "Not sure" is an honest answer and counts as part of the risk, because an unchecked area is usually where the problem is.

Launch risk score
0 / 100
Not started
By area
Top fixes, in order
    Launch check, from $600 CAD
    A self-check, not a test. The score weights each area by how badly it tends to fail in production, and counts "not sure" as partial risk. It tells you where to look first; it cannot confirm the code is safe.

    Questions

    What goes wrong most often in apps built with AI coding tools?

    The same handful of things: keys shipped to the browser, database access rules left open, endpoints that trust whatever ID the browser sends, and prices or permissions enforced only in the UI. The app works in a demo, so nobody notices until someone else looks.

    Does an app that works mean it is safe?

    No. Most of these issues are invisible when you use the app as intended. They show up when someone changes a request, calls an API directly, or reads your JavaScript bundle, which takes minutes with browser developer tools.

    What does the launch check cover?

    We review the code and the running app against the failure modes AI assistants produce, record every check as passed, failed or not applicable, and write up failures with the file, the severity and the fix. Fixes are retested once they land.

    Is this checklist free?

    Yes, free and no signup. Your answers stay in your browser.

    Not ready for a call yet?

    Get your fix list by email

    Your score and top fixes to keep, then a few short notes from Jacob on shipping AI-built apps without the usual holes. Unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Vibe-Coding QA and Launch Check

    A review of AI-generated code with file references and fixes, before you launch.

    Explore Vibe-Coding QA and Launch Check →

    Have someone check it before your users do.

    Our launch check reviews your AI-built app against the failure modes coding assistants produce, with every finding tied to a file and a fix, and a retest once you have fixed them. From $600 CAD for a launch check.

    See the launch check Book a call

    Want the full picture?

    This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

    Start your free assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.