Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Trust Center

Everything you need to trust the engagement.

The frameworks we run, how long they typically take, the industries we serve, and exactly what you walk away with. If your buyer or board is doing diligence on who you would hire, this page is for them.

Book a free readiness call

This page, but for you, built from your workspace

Every client on a live engagement gets a public trust center in their workspace at no extra charge. It is generated from the registers we are already keeping for you, so it cannot drift from your real posture the way a hand-maintained page does. Compliance status per framework, your subprocessors, where data is held, a published security contact, and a request path for the report under NDA. Every section is opt-in, and nothing is ever claimed that your file does not support: a framework with no report on file reads as readiness in progress, never as certified.

Not a client? We can host one for you for a monthly fee. Get in touch and we will tell you what it costs.

What we run, and how long it takes

Timelines assume reasonable starting hygiene and are the readiness portion. For anything with an audit, an independent CPA or accredited body issues the report; we get you ready and coordinate them. The auditor fee is separate.

FrameworkTypical readiness timelineWho asks for it
SOC 2 (Type I / II)8 to 12 weeks to Type I, then the Type II windowUS enterprise and SaaS buyers
ISO 27001~16 weeks to Stage 1Global and European buyers
ISO 42001 (AI)Scoped to your AI footprintEnterprise buyers of AI products
HIPAAScoped; often run alongside SOC 2US healthcare and payers
PCI DSSScope reduction first, then readinessPayment and fintech partners
Quebec Law 25 / PIPEDA~4 weeks for the Law 25 sprintCanadian privacy obligations
NIST CSF / GDPRScoped assessment and roadmapPosture benchmarking, EU data

Every engagement starts with a fixed-scope gap analysis; remediation and audit coordination are scoped afterward. See full pricing.

Who we work with

What you walk away with

Gap analysis

A prioritized, plain-language list of exactly what stands between you and the framework, with effort estimates.

Policies & procedures

The policy set and evidence repository your framework requires, written to what you actually do.

Control implementation

IAM, change management, vendor risk, logging, incident response, and BCP, implemented and documented.

Auditor coordination

We introduce and manage the independent auditor so evidence requests do not stall your team.

Findings & remediation

Security findings ranked by real exploitability with concrete fixes, tracked in your client portal.

A live portal

Findings, evidence requests, documents, milestones, and e-signature in one place. See the traztech Workspace.

Real depth, not a checklist

traztech is led by Jacob Masse, a published security researcher with five CVEs, including CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet. He has stood up a SOC 2 Type II program from scratch across 76 controls and built and exited a security product. You work with that depth directly. See the research or read more about traztech.

Doing diligence on who to hire?

Book a free 30-minute readiness call and get a straight answer.

Book a free readiness call

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.