Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

AI / LLM Security

AI/LLM security is the practice of protecting applications built on large language models and AI agents from threats unique to them, such as prompt injection, data leakage, and model abuse. It addresses risks across the model, its data, its tools, and its outputs. The OWASP Top 10 for LLM Applications is the leading reference for these risks.

In practice

LLM-powered products introduce attack paths traditional security never had to consider: untrusted text becomes executable instruction, retrieval pipelines leak sensitive data, and autonomous agents can be steered into abusing their own tools.

A solid AI security pass combines threat modeling of the model, data, and agent surfaces with adversarial testing against the OWASP LLM Top 10. traztech runs the threat modeling and co-delivers the hands-on adversarial work with our offensive-security partner.

// how traztech helps

traztech delivers AI / LLM security assessments for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

This comes up the moment a product ships a model-backed feature and a buyer asks what the model does with their data. The questions arrive faster than most frameworks have adapted to them.

The failures that matter are architectural rather than prompt-level: what the model can reach, what it retains, what happens to its output downstream, and whether anybody can say which models touch customer data.

AI / LLM Security: common questions

Does SOC 2 cover AI risk?

Not specifically. SOC 2 will ask whether access is controlled and changes are managed. It will not ask whether customer data is used for training or how you evaluate a model for degradation, which buyers ask every time.

What standard covers AI management?

ISO 42001 is the AI management system standard, and the NIST AI RMF is a widely used risk framework. The EU AI Act imposes obligations based on how a system is classified.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.