Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Training, monthly

Security awareness training

From $200/mo CAD · scoped to your team

Onboarding and annual training, phishing simulations and completion tracking, run in your TrazTech workspace. When the auditor asks for training records for SOC 2, ISO 27001, HIPAA, PCI DSS or CyberSecure Canada, they are already there.

Set up training See pricing

Training, simulations and the records

Onboarding training

New hires are enrolled when they join and complete security training in their first weeks, so the on-hire requirement is met without anyone remembering to do it.

Annual training

Everyone completes a refresher every twelve months, measured per person rather than per calendar year.

Phishing simulations

Realistic simulated phishing emails, results per person, and short follow-up training for anyone who clicks.

Current topics

Phishing and social engineering, including AI-enabled attacks such as deepfake voice and video and CEO fraud, acceptable use of company devices and AI tools, passwords and MFA, handling customer data, and how to report an incident.

Completion tracking

Who is done, who is overdue and who has not started, with reminders sent from your TrazTech workspace.

Records ready for an auditor

Dated, per-person completion records and simulation results, exportable when the auditor asks for them.

Set up once, then every month

  1. Setup monthYour roster, who is in scope including contractors, the training schedule, and topics matched to your own policies.
  2. Every monthNew hires enrolled, reminders sent, phishing simulations run, follow-up training assigned, and a monthly report from your workspace.
  3. At audit timeCompletion records and simulation results exported for the auditor, per person and dated.

What each framework asks for

FrameworkWhat it asks for
SOC 2CC1.4, CC2.2Training records and evidence that security responsibilities were communicated
ISO 27001Annex A 6.3Awareness, education and training for staff, relevant to their role
HIPAA45 CFR 164.308(a)(5)A security awareness and training programme for the whole workforce
PCI DSS v4.012.6Training on hire and every twelve months, covering phishing and social engineering, and acceptable use
CyberSecure CanadaCAN/DGSI 104Security awareness training; the 2026 revision names AI-enabled social engineering such as deepfakes and CEO fraud

Training lands best next to a clear policy. Pair it with an AI acceptable use policy so staff know which AI tools they may use and what data stays out, or fold it into CyberSecure Canada, SOC 2 or ISO 27001 work.

Awareness training questions, answered

How is the training delivered?

In your TrazTech workspace. Staff complete the modules there, the phishing simulations run from it, and the completion records and results stay with the rest of your compliance evidence. There is no separate training platform to buy.

Does it satisfy SOC 2, ISO 27001, HIPAA and PCI DSS?

It is built to. Each framework asks for training on hire and on a regular cycle, with records to prove it, and PCI DSS also names phishing and acceptable use as topics. The programme covers those, and the records are what an auditor samples.

Does phishing simulation replace training?

No, it complements it. A simulation shows who is likely to click and gives them targeted follow-up. Auditors still ask for the training records behind it, so you get both.

Do contractors need training too?

Usually yes. Anyone with access to your systems or customer data should be in the programme, and most frameworks reach beyond full-time employees. We enrol whoever is in scope.

What does it cost?

It is monthly, from $200 a month in CAD, scoped to how many people are enrolled and whether phishing simulations are included. The first month sets up your roster, schedule and topics.

Training your auditor can see

Tell us how many people you have and which frameworks you answer to. We will set up the roster and the first round.

Set up training Book a 30-minute call

Free PDFs, no card

Get the incident response plan template

The IR plan template and the vendor security questionnaire as PDFs, plus the readiness checklists. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.