A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Practical SOC 2, HIPAA, and ISO 27001 checklists, a vendor security questionnaire, and an incident response plan template. Drop your email and the download unlocks instantly. No fluff, no sales calls unless you ask.
Every control an auditor samples, grouped by Trust Services Criteria, with why it matters and the evidence they accept. Includes a realistic timeline, common exceptions and Canadian notes. 7 pages.
Download nowThe Security Rule safeguards, business associate duties and breach notification, with the evidence customers and OCR ask for. Written for digital health companies. 5 pages.
Download nowClauses 4 to 10 plus the four Annex A themes of the 2022 edition, including the controls that are new since 2013, with evidence for each and a certification timeline. 7 pages.
Download now31 questions in eight sections, each with what a good answer looks like and the red flags. Use it on your vendors, then answer it yourself before your buyers ask. PDF, plus a fillable Excel sheet with scoring and a Word copy.
Download nowA fill-in plan: roles, severity levels, each response phase, and who to notify under PIPEDA, Quebec Law 25 and your contracts, plus a tabletop exercise to test it. 5 pages.
Download nowThese are starting points, not legal or audit advice. When you are ready to actually get there, traztech runs the readiness as a fixed-scope engagement. Book a free readiness call.
Book a free 30-minute readiness call and we will map your real gaps and quote you.
Book a free readiness callDownloading a policy template is the easy half. traztech Workspace keeps the whole set, tracks which control each one satisfies, prompts you for the details only you know, and prints them as PDFs with your approver and review date on the front.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | A documented readiness position the audit firm can scope and price against | Nothing. The audit firm prices your readiness, not your tooling |
Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.