Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Trust center, self-managed or managed

A trust center that answers your buyers' security reviews for you

Self-managed: free for clients · Hosted: From $149/mo · Managed: From $750/mo CAD

Buyers ask the same security questions on every deal. A trust center answers them up front: we set it up and host it, and on the managed tier we answer the questions and handle NDA document requests for you.

Get a managed trust center quote Set up a self-managed trust center
What is a managed trust center? A trust center that a security specialist operates for you. TrazTech hosts the page, answers inbound security questions, releases your SOC 2 report and policies under NDA once you approve, keeps documents and subprocessors current, and reports monthly on who asked for what. You approve; we do the work.

Want to see one first? We walk you through a live trust center on the call, or draft yours now with the free trust center builder.

Self-managed, hosted or managed

All three are the same trust center, hosted by TrazTech and generated from your compliance workspace. The difference is whether you are a client, and who does the work once buyers start using it.

For clients

Self-managed

Free on a live engagement

We build it, you run it. Included for clients on a live TrazTech engagement, with someone on your side who owns security questions.

  • Setup of your trust center page, on traztech.ca and ready to link from your site
  • Sections you choose: compliance status, policy titles, subprocessors, data locations, security contact, document requests
  • Compliance status read from your workspace, so it never claims more than your file supports
  • Requests for documents go to your own security contact
  • A one-hour handover on handling requests and NDAs well
Set up self-managed
For non-clients

Hosted

From $149/mo

The same self-managed trust center for companies that are not TrazTech clients. We host it; your team runs it.

  • Everything in self-managed: setup, hosting on traztech.ca, the sections you choose
  • A free TrazTech workspace to hold the documents and status the page draws on
  • Requests for documents go to your own security contact
  • Move to managed at any time, or to self-managed if you start an engagement with us
Set up hosted

What each tier covers

What happensSelf-managedHostedManaged
Who it is forClients on a live engagementCompanies that are not clientsAnyone
Trust center setup and hostingTrazTechTrazTechTrazTech
Compliance status kept in step with your workspaceIncludedIncludedIncluded
Answering inbound security questionsYour teamYour teamTrazTech, one business day first-response target
SOC 2 report and policy requests under NDAYour teamYour teamTrazTech, released on your approval
Record of who received which document, whenYour teamYour teamTrazTech
Keeping reports, letters, policies and dates currentYour teamYour teamTrazTech
Subprocessor change notices to buyersYour teamYour teamTrazTech
Monthly activity and buyer reportNot includedNot includedIncluded
Full security questionnairesSeparate serviceSeparate serviceOptional add-on, quoted
Price (CAD)FreeFrom $149/moFrom $750/mo

Response targets are agreed with you at onboarding and written into your quote.

Questionnaires, when a buyer still sends one

A good trust center prevents many questionnaires and shortens the rest. When a buyer sends a full SIG Lite, CAIQ, VSA or custom spreadsheet, the managed tier can add questionnaire handling: we complete it from your answer library and workspace evidence, ask you only what needs your input, and return it in the buyer's format. It is quoted separately, since one questionnaire can be an afternoon or a week.

Facing a single urgent questionnaire without a trust center? That is security questionnaire help, and a buyer's full review with calls and follow-up is enterprise security review support.

The page your buyers read

  • Compliance status per framework, stated honestly. A framework with no report on file reads as in progress, never as certified.
  • Subprocessors: who else touches customer data and why. Buyers ask for this by name.
  • Where data is held, by city and country, which matters to Canadian buyers under PIPEDA and Quebec Law 25.
  • Policy titles if you choose, never the text; the policies go out under NDA.
  • A security contact and vulnerability disclosure line.
  • A way to request the documents: your SOC 2 report, ISO 27001 certificate, pentest attestation letter and policies, released one request at a time.

Nothing sensitive is published: no findings, no risks, no evidence and no counts that would reveal a gap. Every section is opt-in, so you decide what is published.

From call to live trust center

  1. A 30-minute call (day 1)What you sell, who your buyers are, how many security requests you get, which frameworks you hold or are working toward. You leave with a written quote for the managed tier, or a setup date for self-managed or hosted.
  2. Your fileWe collect what the page will draw on: reports and certificates, your policy set, subprocessors and data locations. If you are already a TrazTech client this is already in your workspace.
  3. Approval rules (managed)We agree who approves document releases, which NDA we use (yours or a standard mutual NDA), which questions we can answer without asking you, and the response targets.
  4. LaunchYou review the page, we publish it, and you link it from your site footer, your security page and your sales email signatures.
  5. Every month (managed)We handle requests as they arrive, keep documents current, and send you the activity report with the buyer signals in it.

Built for teams that...

  • Answer the same security questions on every enterprise deal
  • Just finished a SOC 2 or ISO 27001 and want buyers to see it without a week of email
  • Have no one whose job is procurement security, so it lands on a founder or a senior engineer
  • Sell into Canadian public sector, finance or health, where data location and subprocessors are asked first
  • Are working toward a framework and want to show honest progress while they do

Our principal took a venture-backed company from no programme to a SOC 2 Type II with zero exceptions: how it was built. The trust center is where that work pays off in sales.

Trust center questions, answered

What is a managed trust center?

A managed trust center is a public security page that a specialist runs for you. TrazTech hosts the page, answers the security questions buyers send through it, handles requests for your SOC 2 report and policies under NDA, and keeps the documents and subprocessor list current. You approve what is shared; we do the work and send you a monthly summary.

What is the difference between self-managed, hosted and managed?

Self-managed and hosted are the same trust center run by your own team: you answer the requests, send the documents and keep it current. Self-managed is free for clients on a live TrazTech engagement; hosted is the same thing for companies that are not clients. Managed means TrazTech does that work on your behalf and your team only approves what goes out.

How much does a trust center cost?

Self-managed is free for clients on a live engagement. Hosted is From $149/mo and managed is From $750/mo, in CAD. The managed price depends on how many requests you receive, how many frameworks and documents you publish, and whether you want questionnaires included.

How is my SOC 2 report shared?

Never as a public download. A buyer requests it, confirms who they are, and receives it once an NDA is in place and you have approved the release. On the managed tier TrazTech handles each of those steps and keeps a record of who received what and when.

Can I have a trust center before I have SOC 2 or ISO 27001?

Yes. The page states honestly where each framework stands, for example in progress, and publishes your subprocessors, data locations, policies and security contact. That answers most of what an early buyer asks. It never claims a certification you do not hold.

Related work

Stop answering the same security questions by hand

Tell us how many security requests you get and what you hold today. We will reply with a written quote for the managed tier. Still working toward a framework? Start with a SOC 2 or ISO 27001 gap analysis.

Get a managed trust center quote Book a 30-minute call

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.