A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Every engagement starts the same way and runs in a workspace you keep. What happens in the middle depends on the service, so it is set out below by type of work.
SOC 2, ISO 27001, ISO 42001, CyberSecure Canada, HIPAA, PCI DSS, GDPR, PIPEDA, Quebec Law 25 and NIST CSF all run the same way, on one record per framework.
Fixed price. One request list for the documents and access we need, walked through on the onboarding call. Every control assessed, findings ranked, and a gap report you keep whether or not you continue.
Fixed price, scoped from the gap. Findings carry over with nothing re-entered: policies, controls and evidence, then auditor selection, handoff and support through to your report or certificate.
Continuous compliance between audits: evidence, monitoring, policy and access reviews, vendor reviews, and audit readiness each cycle. Light most months, more in audit months.
Already on Drata, Vanta or a similar platform? We work inside it. If not, the free workspace does the job. See all compliance services.
Penetration testing, vulnerability assessment, AI and LLM security, LLM red teaming, vibe-coded app QA and cloud security review.
Enterprise security review, threat and risk assessment, technical due diligence, internal audit and cloud cost audit. Scope agreed in writing, an intake checklist in your workspace, interviews and evidence review, then a formal report with a risk-ranked roadmap and a readout.
vCISO, continuous compliance, vulnerability management, outsourced privacy officer, vendor risk reviews, incident response retainer, managed trust center and awareness training. The first month is onboarding: your environment, registers and open risks reviewed, and a plan agreed. Then a standing cadence, a monthly report from your workspace, and hours you can see. A vCISO can be a monthly block of hours or flexible on actual hours.
Investors use us for technical due diligence on a target or across a portfolio. MSPs and IT firms use us to deliver compliance and testing to their own clients through our partner program; the client relationship stays theirs.
It depends on what the gap analysis finds, not on a fixed track. SOC 2 Type I commonly takes a few months from start to report. Type II adds an observation window of 3, 6 or 12 months. ISO 27001 certification commonly takes several months, including the Stage 1 and Stage 2 audits. The drivers are the gaps, the observation period and the auditor's schedule. We give you a realistic plan after Phase 1.
One person who can make decisions about scope, named owners for the controls, and the items on your request list. The kickoff call walks through that list with you, so you only work on what applies.
Yes. Give us a seat and we work where your evidence already lives. If you do not use one, your free TrazTech workspace does the same job.
Yes. We issue a letter confirming the engagement before testing starts, and an attestation letter once the report is out.
Yes. Questions about how we tested, what we reviewed or how a finding was closed come to us, and we answer them directly.
You keep the deliverables and the workspace. We suggest the natural next step, such as Phase 2, a retest or ongoing upkeep, and you decide.