Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Got questions?

General Questions
What types of companies do you work with?
We work with Canadian startups, SMEs and scale-ups, and the range is wider than people assume: pre-seed startups with a first enterprise prospect asking for a report, established SMEs, and growing companies running several frameworks at once. Recent work includes a data centre operator of around twenty people and a VC-backed medtech company. There is no minimum stage and no minimum headcount. What matters is whether security or compliance is on your critical path.
How quickly can you start?
The start date is agreed in the proposal, usually soon after signing. How long the work runs depends on what the gap analysis finds and, where there is an audit, on the observation period and the auditor's or certification body's schedule. SOC 2 Type I is commonly a few months from start to report, and Type II adds a 3, 6 or 12 month observation window. If you have an audit date or a buyer deadline already, tell us what it is and we will say plainly whether it is achievable rather than agreeing and hoping.
What makes traztech different from other consulting firms?
Two things. The work is led by a published vulnerability researcher with five CVEs, including a CVSS 9.1 in the Mirai botnet, so the security advice comes from someone who finds these problems rather than reads about them. And the prices are fixed and published: you can see the number before you speak to anybody. Most firms in this space quote hours and tell you the total afterwards.
Pricing & Engagement
How do you structure your pricing?
Fixed scope, fixed price, published on our pricing page. A SOC 2 gap analysis starts from $3,000, penetration testing and larger programmes are scoped to a defined deliverable, and retainers are offered where ongoing cover genuinely makes sense. Any third-party auditor or certification body fee is separate and paid directly to them, which we say up front because it is the line that surprises people.
What's your minimum engagement period?
There is no minimum for project work. A gap analysis, a penetration test or a readiness engagement is a defined piece of work with an end. For ongoing security leadership we suggest three months, simply because less than that rarely changes anything, but nothing locks you in beyond the work you have agreed.
Services & Expertise
Do you offer fractional leadership beyond security?
We provide fractional CISO only. That is security leadership: owning your security programme, handling questionnaires and buyer reviews, running incident response readiness, and being accountable for the roadmap. We do not offer engineering or operations leadership. If your gap is engineering leadership rather than security, we would rather tell you that than sell you the nearest thing we have.
Can you help with SOC 2 compliance?
Yes, and it is the single thing we are asked for most. SOC 2 readiness starts with a fixed-price gap analysis, then remediation and dealing with the auditor through to the report, scoped from what the gap finds. Our principal previously took a venture-backed company from no compliance programme at all to a SOC 2 Type II with zero exceptions. We also run ISO 27001, HIPAA, PCI DSS, NIST CSF and the Canadian privacy stack, and frequently run two frameworks together where the overlap makes that cheaper than doing them in sequence.
Can you fail a SOC 2 audit?
Yes, though not as a pass or fail stamp. A CPA firm issues an opinion, and both an adverse opinion and a disclaimer are real, damaging outcomes. ISO 27001 is blunter still: a major nonconformity at Stage 2 withholds the certificate until the fix is verified, at audit days you pay for. The outcome that catches most unprepared companies is worse than a bad report. The auditor reaches fieldwork, finds the evidence is not testable, and recommends pausing, so you have paid for an audit that produced nothing you can send a buyer, re-entering fieldwork means paying a firm again, and a Type II gap can add a fresh three to twelve month observation window. What a stalled audit costs.
Our compliance dashboard is all green. Do we still need help?
Green means the checks the platform can automate are passing. A platform reads your cloud configuration and your device fleet. It cannot confirm that your access review actually ran with a named reviewer, that your incident response plan has ever been tested, or that the change management policy you uploaded describes how your team really deploys. Those gaps are where exceptions get written, and closing them is still work a person has to do.
Do you provide ongoing support or just one-time projects?
Both. Most companies start with one defined piece of work, a gap analysis or a readiness engagement, and some continue into an ongoing arrangement such as fractional CISO cover, vulnerability management or an incident response retainer. Neither requires the other. A one-off engagement is a complete piece of work, not a trial.
What technologies and tools do you work with?
We work across AWS, GCP and Azure, the usual identity providers, and whatever your stack already is. We are not reselling a compliance platform: our workspace is free to use, holds the control sets, evidence register and policy templates, and you keep it whether or not you work with us. If you already run a commercial compliance tool we will work inside it.
Getting Started
What's your onboarding process?
A short scoping conversation, then a written proposal with the scope, the deliverable, the timeline and the price. Once accepted, we run a kickoff, agree the boundary of what is in scope, and issue the evidence request list, built for your framework and scope and walked through on the kickoff call. It is the point at which most companies learn what their real position is.
How do you measure success?
By whether the thing you needed happened. A report issued without exceptions. A questionnaire that stops blocking a deal. A penetration test with findings that got fixed rather than filed. We agree what that looks like before starting, and if we do not think a fixed scope will get you there, we say so on the call and quote it properly instead.
Do you sign NDAs and work contracts?
Yes. We sign mutual NDAs, work under your MSA if you have one, and have our own agreement if you do not. Everyone working on your engagement is bound by confidentiality obligations, and for security work we will also sign whatever scope authorisation your side needs before anything is tested.
No questions match your search. Try different keywords or contact us directly.

Still have questions?

We would love to hear from you. Book a call and let's talk about what you need.

The same work, without the line item

Every readiness programme needs a control library, an evidence register, policies and a score for the board. Being quoted five figures a year for that is normal. Paying it is not.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote A documented readiness position the audit firm can scope and price against Nothing. The audit firm prices your readiness, not your tooling

Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.