A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Onboarding and annual training, phishing simulations and completion tracking, run in your TrazTech workspace. When the auditor asks for training records for SOC 2, ISO 27001, HIPAA, PCI DSS or CyberSecure Canada, they are already there.
New hires are enrolled when they join and complete security training in their first weeks, so the on-hire requirement is met without anyone remembering to do it.
Everyone completes a refresher every twelve months, measured per person rather than per calendar year.
Realistic simulated phishing emails, results per person, and short follow-up training for anyone who clicks.
Phishing and social engineering, including AI-enabled attacks such as deepfake voice and video and CEO fraud, acceptable use of company devices and AI tools, passwords and MFA, handling customer data, and how to report an incident.
Who is done, who is overdue and who has not started, with reminders sent from your TrazTech workspace.
Dated, per-person completion records and simulation results, exportable when the auditor asks for them.
| Framework | What it asks for |
|---|---|
| SOC 2CC1.4, CC2.2 | Training records and evidence that security responsibilities were communicated |
| ISO 27001Annex A 6.3 | Awareness, education and training for staff, relevant to their role |
| HIPAA45 CFR 164.308(a)(5) | A security awareness and training programme for the whole workforce |
| PCI DSS v4.012.6 | Training on hire and every twelve months, covering phishing and social engineering, and acceptable use |
| CyberSecure CanadaCAN/DGSI 104 | Security awareness training; the 2026 revision names AI-enabled social engineering such as deepfakes and CEO fraud |
Training lands best next to a clear policy. Pair it with an AI acceptable use policy so staff know which AI tools they may use and what data stays out, or fold it into CyberSecure Canada, SOC 2 or ISO 27001 work.
In your TrazTech workspace. Staff complete the modules there, the phishing simulations run from it, and the completion records and results stay with the rest of your compliance evidence. There is no separate training platform to buy.
It is built to. Each framework asks for training on hire and on a regular cycle, with records to prove it, and PCI DSS also names phishing and acceptable use as topics. The programme covers those, and the records are what an auditor samples.
No, it complements it. A simulation shows who is likely to click and gives them targeted follow-up. Auditors still ask for the training records behind it, so you get both.
Usually yes. Anyone with access to your systems or customer data should be in the programme, and most frameworks reach beyond full-time employees. We enrol whoever is in scope.
It is monthly, from $200 a month in CAD, scoped to how many people are enrolled and whether phishing simulations are included. The first month sets up your roster, schedule and topics.
Tell us how many people you have and which frameworks you answer to. We will set up the roster and the first round.
Free PDFs, no card
The IR plan template and the vendor security questionnaire as PDFs, plus the readiness checklists. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
We would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.
The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.