Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Independent assurance

Internal audit for ISO 27001 and ISO 42001

From $3,000 CAD per audit · scoped to you

An independent clause 9.2 internal audit of your management system, ahead of your certification or surveillance audit. You get a report with nonconformities and observations, and we check your corrective actions before it is final.

Scope an internal audit See pricing
Independence first. We only offer internal audit where we have not operated your controls, and we never fix what we audited.

Plan, fieldwork, report

01

Audit plan

Scope, criteria, sampling approach, who we will interview and when, agreed with you before fieldwork starts.

02

Remote fieldwork

Interviews by video, document review, and samples of your records tested against the clauses and controls in scope. We test what you do, not only what the policy says.

03

Draft report

Nonconformities, graded major or minor, and observations, each tied to the clause or control it concerns.

04

Corrective action check

You respond with a root cause and corrective actions. We check them once, before the final report, and record what we saw.

05

Final report

Ready for your management review and for the certification body at your next audit.

Audit all of it, or part of it each time

Clause 9.2 asks for audits at planned intervals, so the programme can be spread across the certification cycle. Pick the scope that fits this audit.

Full

Clauses 4 to 10 and every applicable Annex A control in one audit.

Clauses only

The management system requirements, clauses 4 to 10, without the Annex A controls.

Annex only

The Annex A controls in your Statement of Applicability, without the clauses.

Rotating programme

Selected Annex themes each time, rotated so every clause and control is covered across the certification cycle. We track coverage so nothing is missed before recertification.

Not a gap analysis, not remediation

A gap analysis tells you what is missing before you build. An internal audit tests whether the system you already run conforms, and only an internal audit counts as clause 9.2 evidence. Not built yet? Start with a gap analysis for ISO 27001 or ISO 42001.

Consultancies and MSPs have the same independence problem with their own clients. We take internal audit referrals on a ring-fenced basis: we audit, report to the client's management, and do not offer them our readiness work. See the MSP partner programme.

The natural next step is next year's internal audit, or the next themes in your rotation.

Internal audit questions, answered

Does ISO 27001 require an internal audit?

Yes. Clause 9.2 requires internal audits at planned intervals and an audit programme, and it cannot be excluded the way an Annex A control can. ISO 42001 has the same clause for an AI management system. The certification body will ask for your internal audit records at the certification audit and at each surveillance audit.

Why can you not audit a programme you run?

Clause 9.2 requires auditors to be chosen so the audit is objective and impartial, and nobody is impartial about controls they operate. So we only offer internal audit where we have not operated your controls. If we run your programme, we will say so and help you find an independent auditor.

Can you audit only part of the standard?

Yes. Choose a full audit, the clauses only, the Annex A controls only, or selected Annex themes in a rotating programme. With the rotation we track coverage across the cycle so every clause and control is audited before recertification.

Do you fix the nonconformities you find?

No. Fixing what we audited would end our independence. You, or whoever runs your programme, correct them; we check the corrective actions once before the final report.

Is fieldwork done on site?

Fieldwork is remote: interviews by video, and documents and records sampled through your workspace or a shared screen. The audit plan sets out how each control in scope will be tested.

Book the audit before the auditor arrives

Tell us the standard, your certification or surveillance date and the scope you have in mind. We will confirm we are independent of your controls and send a fixed price.

Scope an internal audit Book a 30-minute call

Free PDFs, no card

Get the checklists that go with this

The SOC 2 readiness checklist, the ISO 27001 gap checklist and the vendor security questionnaire, as PDFs you can print or hand to your team. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.