A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →We act as your named privacy officer: the Quebec Law 25 person in charge, your PIPEDA designated individual and your GDPR contact. We answer the requests, run the assessments and keep your privacy programme current, every month.
For Quebec Law 25, the person in charge of the protection of personal information, by written delegation from your highest authority, with the title and contact details published on your website. For PIPEDA, your designated individual. For GDPR, the contact point for individuals and authorities.
Each request received, the requester verified, the data located and the answer sent within the deadline: 30 days under PIPEDA and Law 25, one month under GDPR. Every request is logged with what was sent and when.
Your privacy policy, the governance policies Law 25 asks you to publish, retention and destruction rules, and your inventory of personal information, kept current as the business changes.
Run when a project needs one: a new or overhauled system that handles personal information, a transfer of personal information outside Quebec, or high-risk processing under GDPR.
Each incident assessed against the test of each law that applies. Law 25 confidentiality incidents go into your incident register, and the Commission and the people affected are notified when there is a risk of serious injury. PIPEDA breach records are kept for 24 months, with reports where there is a real risk of significant harm.
Privacy sections of security questionnaires, data processing agreement questions, complaints and regulator inquiries, answered or drafted for your approval.
| Law | The role | How we hold it |
|---|---|---|
| Quebec Law 25 | Person in charge of the protection of personal information | Written delegation from your highest authority; title and contact details published on your website. |
| PIPEDA | Designated individual accountable for compliance | Named in your privacy policy and given on request. |
| GDPR | Contact point for individuals and supervisory authorities | Named in your privacy notice. Where you must designate a data protection officer, we can be appointed externally under Article 37(6). |
We cannot act as your EU representative under GDPR Article 27, which must be established in the EU. We will tell you if you need one.
If the onboarding review finds real gaps, a fixed-price gap analysis against Quebec Law 25, PIPEDA or GDPR closes them properly. Vendors who handle your personal information are covered by vendor risk management.
Yes. Under Law 25 the person with the highest authority in your organization is the person in charge of the protection of personal information by default, and may delegate that function in writing, in whole or in part, to someone inside or outside the organization. We sign that delegation with you and publish the title and contact details on your website.
Your organization. The function is delegated to us; the legal obligations remain yours. We carry out the work, keep the records and tell you when a decision needs you, such as approving a notice or a new use of personal information.
Within 30 days under PIPEDA and Quebec Law 25, and within one month under GDPR. Each law allows an extension in limited cases. We track the deadline from the day the request arrives and log the answer.
We assess it against each law that applies. Under Law 25 every confidentiality incident goes into your register, and the Commission d'accès à l'information and the people affected are notified promptly when there is a risk of serious injury. Under PIPEDA every breach is recorded and the record kept for 24 months, with a report to the Privacy Commissioner and notices to individuals where there is a real risk of significant harm. GDPR has its own notification test and deadline, which we apply where it covers you.
It is a monthly retainer, from $750 a month in CAD, scoped to which laws apply to you and how many requests and assessments you expect. The first month covers onboarding: the delegation, the published contact, and a review of your policies, requests and open incidents.
Tell us which laws apply and how many requests you get. We will tell you what the role involves for you and what it costs.
Free PDFs, no card
The template set as PDFs, including the vendor security questionnaire and the incident response plan, which are the two that come up first in a privacy review. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.