Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Privacy, monthly

Outsourced privacy officer

From $750/mo CAD · scoped to you

We act as your named privacy officer: the Quebec Law 25 person in charge, your PIPEDA designated individual and your GDPR contact. We answer the requests, run the assessments and keep your privacy programme current, every month.

Talk about the role Check your Law 25 officer setup
Your organization stays accountable. The function is delegated to us in writing; the legal obligations remain yours. We do the work, keep the records and bring you the decisions that need you.

The work that comes with the title

Your named privacy officer

For Quebec Law 25, the person in charge of the protection of personal information, by written delegation from your highest authority, with the title and contact details published on your website. For PIPEDA, your designated individual. For GDPR, the contact point for individuals and authorities.

Access and deletion requests

Each request received, the requester verified, the data located and the answer sent within the deadline: 30 days under PIPEDA and Law 25, one month under GDPR. Every request is logged with what was sent and when.

Privacy programme and policies

Your privacy policy, the governance policies Law 25 asks you to publish, retention and destruction rules, and your inventory of personal information, kept current as the business changes.

Privacy impact assessments

Run when a project needs one: a new or overhauled system that handles personal information, a transfer of personal information outside Quebec, or high-risk processing under GDPR.

Breach and incident obligations

Each incident assessed against the test of each law that applies. Law 25 confidentiality incidents go into your incident register, and the Commission and the people affected are notified when there is a risk of serious injury. PIPEDA breach records are kept for 24 months, with reports where there is a real risk of significant harm.

Questions from customers and regulators

Privacy sections of security questionnaires, data processing agreement questions, complaints and regulator inquiries, answered or drafted for your approval.

The role each law asks for

LawThe roleHow we hold it
Quebec Law 25Person in charge of the protection of personal informationWritten delegation from your highest authority; title and contact details published on your website.
PIPEDADesignated individual accountable for complianceNamed in your privacy policy and given on request.
GDPRContact point for individuals and supervisory authoritiesNamed in your privacy notice. Where you must designate a data protection officer, we can be appointed externally under Article 37(6).

We cannot act as your EU representative under GDPR Article 27, which must be established in the EU. We will tell you if you need one.

From delegation to a monthly cadence

  1. Call and scopeWhich laws apply, how much personal information you hold, and how many requests and projects you expect. Not sure which laws apply? The privacy law finder tells you for free.
  2. Onboarding monthThe written delegation signed, our contact details published, your policies, personal information inventory, open requests and past incidents reviewed, and a plan agreed.
  3. Every monthRequests answered on time, assessments run as projects come up, registers kept current, questions answered, and a monthly report from your TrazTech workspace.

Where gaps turn up

If the onboarding review finds real gaps, a fixed-price gap analysis against Quebec Law 25, PIPEDA or GDPR closes them properly. Vendors who handle your personal information are covered by vendor risk management.

Privacy officer questions, answered

Can the Law 25 privacy officer be outsourced?

Yes. Under Law 25 the person with the highest authority in your organization is the person in charge of the protection of personal information by default, and may delegate that function in writing, in whole or in part, to someone inside or outside the organization. We sign that delegation with you and publish the title and contact details on your website.

Who stays accountable?

Your organization. The function is delegated to us; the legal obligations remain yours. We carry out the work, keep the records and tell you when a decision needs you, such as approving a notice or a new use of personal information.

How quickly do access and deletion requests have to be answered?

Within 30 days under PIPEDA and Quebec Law 25, and within one month under GDPR. Each law allows an extension in limited cases. We track the deadline from the day the request arrives and log the answer.

What happens when there is a breach or confidentiality incident?

We assess it against each law that applies. Under Law 25 every confidentiality incident goes into your register, and the Commission d'accès à l'information and the people affected are notified promptly when there is a risk of serious injury. Under PIPEDA every breach is recorded and the record kept for 24 months, with a report to the Privacy Commissioner and notices to individuals where there is a real risk of significant harm. GDPR has its own notification test and deadline, which we apply where it covers you.

What does it cost?

It is a monthly retainer, from $750 a month in CAD, scoped to which laws apply to you and how many requests and assessments you expect. The first month covers onboarding: the delegation, the published contact, and a review of your policies, requests and open incidents.

Put a privacy officer in the seat

Tell us which laws apply and how many requests you get. We will tell you what the role involves for you and what it costs.

Talk about the role Book a 30-minute call

Free PDFs, no card

Get the privacy readiness checklists

The template set as PDFs, including the vendor security questionnaire and the incident response plan, which are the two that come up first in a privacy review. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.