Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

How an engagement works

Every engagement starts the same way and runs in a workspace you keep. What happens in the middle depends on the service, so it is set out below by type of work.

Book a free 30-minute call See pricing

What every engagement shares

  1. A scoping callThirty minutes to understand what you need, who is asking for it and whether we are the right fit.
  2. A proposal, then the agreementScope and price in writing. Testing work adds an authorization to test, signed before anything is touched.
  3. Kickoff and intakeA kickoff call, then a short intake in your workspace: what we need, the access we need and who we will work with.
  4. The workTracked in your workspace, so you always see what is done and what is waiting on whom.
  5. The deliverable and a readoutYour report or deliverable, walked through on a call, with letters for buyers or auditors where you need them.
  6. What comes nextWe suggest the natural next step, and you decide. You keep everything either way.

Compliance programmes

SOC 2, ISO 27001, ISO 42001, CyberSecure Canada, HIPAA, PCI DSS, GDPR, PIPEDA, Quebec Law 25 and NIST CSF all run the same way, on one record per framework.

Phase 1

Gap analysis

Fixed price. One request list for the documents and access we need, walked through on the onboarding call. Every control assessed, findings ranked, and a gap report you keep whether or not you continue.

Phase 2

Remediation and audit

Fixed price, scoped from the gap. Findings carry over with nothing re-entered: policies, controls and evidence, then auditor selection, handoff and support through to your report or certificate.

Phase 3

Keep it running

Continuous compliance between audits: evidence, monitoring, policy and access reviews, vendor reviews, and audit readiness each cycle. Light most months, more in audit months.

Already on Drata, Vanta or a similar platform? We work inside it. If not, the free workspace does the job. See all compliance services.

Security testing

Penetration testing, vulnerability assessment, AI and LLM security, LLM red teaming, vibe-coded app QA and cloud security review.

Assessments with one report

Enterprise security review, threat and risk assessment, technical due diligence, internal audit and cloud cost audit. Scope agreed in writing, an intake checklist in your workspace, interviews and evidence review, then a formal report with a risk-ranked roadmap and a readout.

Retainers and ongoing work

vCISO, continuous compliance, vulnerability management, outsourced privacy officer, vendor risk reviews, incident response retainer, managed trust center and awareness training. The first month is onboarding: your environment, registers and open risks reviewed, and a plan agreed. Then a standing cadence, a monthly report from your workspace, and hours you can see. A vCISO can be a monthly block of hours or flexible on actual hours.

For investors and MSPs

Investors use us for technical due diligence on a target or across a portfolio. MSPs and IT firms use us to deliver compliance and testing to their own clients through our partner program; the client relationship stays theirs.

Questions

How long does SOC 2 or ISO 27001 take?

It depends on what the gap analysis finds, not on a fixed track. SOC 2 Type I commonly takes a few months from start to report. Type II adds an observation window of 3, 6 or 12 months. ISO 27001 certification commonly takes several months, including the Stage 1 and Stage 2 audits. The drivers are the gaps, the observation period and the auditor's schedule. We give you a realistic plan after Phase 1.

What do you need from our team?

One person who can make decisions about scope, named owners for the controls, and the items on your request list. The kickoff call walks through that list with you, so you only work on what applies.

We already use Drata or Vanta. Can you work in it?

Yes. Give us a seat and we work where your evidence already lives. If you do not use one, your free TrazTech workspace does the same job.

A buyer needs proof the test is booked. Can you help?

Yes. We issue a letter confirming the engagement before testing starts, and an attestation letter once the report is out.

Will you answer our auditor's or customer's questions about your work?

Yes. Questions about how we tested, what we reviewed or how a finding was closed come to us, and we answer them directly.

What happens when the engagement ends?

You keep the deliverables and the workspace. We suggest the natural next step, such as Phase 2, a retest or ongoing upkeep, and you decide.

Book a free 30-minute call