Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →The frameworks we run, how long they typically take, the industries we serve, and exactly what you walk away with. If your buyer or board is doing diligence on who you would hire, this page is for them.
Book a free readiness callEvery client on a live engagement gets a public trust center in their workspace at no extra charge. It is generated from the registers we are already keeping for you, so it cannot drift from your real posture the way a hand-maintained page does. Compliance status per framework, your subprocessors, where data is held, a published security contact, and a request path for the report under NDA. Every section is opt-in, and nothing is ever claimed that your file does not support: a framework with no report on file reads as readiness in progress, never as certified.
Not a client? We can host one for you for a monthly fee. Get in touch and we will tell you what it costs.
Timelines assume reasonable starting hygiene and are the readiness portion. For anything with an audit, an independent CPA or accredited body issues the report; we get you ready and coordinate them. The auditor fee is separate.
| Framework | Typical readiness timeline | Who asks for it |
|---|---|---|
| SOC 2 (Type I / II) | 8 to 12 weeks to Type I, then the Type II window | US enterprise and SaaS buyers |
| ISO 27001 | ~16 weeks to Stage 1 | Global and European buyers |
| ISO 42001 (AI) | Scoped to your AI footprint | Enterprise buyers of AI products |
| HIPAA | Scoped; often run alongside SOC 2 | US healthcare and payers |
| PCI DSS | Scope reduction first, then readiness | Payment and fintech partners |
| Quebec Law 25 / PIPEDA | ~4 weeks for the Law 25 sprint | Canadian privacy obligations |
| NIST CSF / GDPR | Scoped assessment and roadmap | Posture benchmarking, EU data |
Every engagement starts with a fixed-scope gap analysis; remediation and audit coordination are scoped afterward. See full pricing.
SOC 2 and PCI DSS under one program, built for bank diligence.
The SOC 2 and ISO 27001 that unblock enterprise deals as you move up-market.
HIPAA and PHIPA readiness for digital health selling into US healthcare.
ISO 42001, AI security testing, and governance for teams shipping AI.
Ecommerce, logistics, mid-market, and nonprofits. See all industries.
A prioritized, plain-language list of exactly what stands between you and the framework, with effort estimates.
The policy set and evidence repository your framework requires, written to what you actually do.
IAM, change management, vendor risk, logging, incident response, and BCP, implemented and documented.
We introduce and manage the independent auditor so evidence requests do not stall your team.
Security findings ranked by real exploitability with concrete fixes, tracked in your client portal.
Findings, evidence requests, documents, milestones, and e-signature in one place. See the traztech Workspace.
traztech is led by Jacob Masse, a published security researcher with five CVEs, including CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet. He has stood up a SOC 2 Type II program from scratch across 76 controls and built and exited a security product. You work with that depth directly. See the research or read more about traztech.
Book a free 30-minute readiness call and get a straight answer.
Book a free readiness callTrack record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.