A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Buyers ask the same security questions on every deal. A trust center answers them up front: we set it up and host it, and on the managed tier we answer the questions and handle NDA document requests for you.
Want to see one first? We walk you through a live trust center on the call, or draft yours now with the free trust center builder.
All three are the same trust center, hosted by TrazTech and generated from your compliance workspace. The difference is whether you are a client, and who does the work once buyers start using it.
We build it, you run it. Included for clients on a live TrazTech engagement, with someone on your side who owns security questions.
The same self-managed trust center for companies that are not TrazTech clients. We host it; your team runs it.
We host it and run it. Right for teams losing engineering days to procurement, or selling into buyers who expect answers the same day.
| What happens | Self-managed | Hosted | Managed |
|---|---|---|---|
| Who it is for | Clients on a live engagement | Companies that are not clients | Anyone |
| Trust center setup and hosting | TrazTech | TrazTech | TrazTech |
| Compliance status kept in step with your workspace | Included | Included | Included |
| Answering inbound security questions | Your team | Your team | TrazTech, one business day first-response target |
| SOC 2 report and policy requests under NDA | Your team | Your team | TrazTech, released on your approval |
| Record of who received which document, when | Your team | Your team | TrazTech |
| Keeping reports, letters, policies and dates current | Your team | Your team | TrazTech |
| Subprocessor change notices to buyers | Your team | Your team | TrazTech |
| Monthly activity and buyer report | Not included | Not included | Included |
| Full security questionnaires | Separate service | Separate service | Optional add-on, quoted |
| Price (CAD) | Free | From $149/mo | From $750/mo |
Response targets are agreed with you at onboarding and written into your quote.
A good trust center prevents many questionnaires and shortens the rest. When a buyer sends a full SIG Lite, CAIQ, VSA or custom spreadsheet, the managed tier can add questionnaire handling: we complete it from your answer library and workspace evidence, ask you only what needs your input, and return it in the buyer's format. It is quoted separately, since one questionnaire can be an afternoon or a week.
Facing a single urgent questionnaire without a trust center? That is security questionnaire help, and a buyer's full review with calls and follow-up is enterprise security review support.
Nothing sensitive is published: no findings, no risks, no evidence and no counts that would reveal a gap. Every section is opt-in, so you decide what is published.
Our principal took a venture-backed company from no programme to a SOC 2 Type II with zero exceptions: how it was built. The trust center is where that work pays off in sales.
A managed trust center is a public security page that a specialist runs for you. TrazTech hosts the page, answers the security questions buyers send through it, handles requests for your SOC 2 report and policies under NDA, and keeps the documents and subprocessor list current. You approve what is shared; we do the work and send you a monthly summary.
Self-managed and hosted are the same trust center run by your own team: you answer the requests, send the documents and keep it current. Self-managed is free for clients on a live TrazTech engagement; hosted is the same thing for companies that are not clients. Managed means TrazTech does that work on your behalf and your team only approves what goes out.
Self-managed is free for clients on a live engagement. Hosted is From $149/mo and managed is From $750/mo, in CAD. The managed price depends on how many requests you receive, how many frameworks and documents you publish, and whether you want questionnaires included.
Never as a public download. A buyer requests it, confirms who they are, and receives it once an NDA is in place and you have approved the release. On the managed tier TrazTech handles each of those steps and keeps a record of who received what and when.
Yes. The page states honestly where each framework stands, for example in progress, and publishes your subprocessors, data locations, policies and security contact. That answers most of what an early buyer asks. It never claims a certification you do not hold.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.