Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Free templates & checklists

Compliance templates that save you a blank page.

Practical SOC 2, HIPAA, and ISO 27001 checklists, a vendor security questionnaire, and an incident response plan template. Drop your email and the download unlocks instantly. No fluff, no sales calls unless you ask.

SOC 2 Readiness Checklist

Every control an auditor samples, grouped by Trust Services Criteria, with why it matters and the evidence they accept. Includes a realistic timeline, common exceptions and Canadian notes. 7 pages.

Download now

HIPAA Audit Prep Checklist

The Security Rule safeguards, business associate duties and breach notification, with the evidence customers and OCR ask for. Written for digital health companies. 5 pages.

Download now

ISO 27001 Gap Checklist

Clauses 4 to 10 plus the four Annex A themes of the 2022 edition, including the controls that are new since 2013, with evidence for each and a certification timeline. 7 pages.

Download now

Vendor Security Questionnaire

31 questions in eight sections, each with what a good answer looks like and the red flags. Use it on your vendors, then answer it yourself before your buyers ask. PDF, plus a fillable Excel sheet with scoring and a Word copy.

Download now

Incident Response Plan Template

A fill-in plan: roles, severity levels, each response phase, and who to notify under PIPEDA, Quebec Law 25 and your contracts, plus a tabletop exercise to test it. 5 pages.

Download now

These are starting points, not legal or audit advice. When you are ready to actually get there, traztech runs the readiness as a fixed-scope engagement. Book a free readiness call.

Rather have us just do it?

Book a free 30-minute readiness call and we will map your real gaps and quote you.

Book a free readiness call

The templates, with somewhere to put them

Downloading a policy template is the easy half. traztech Workspace keeps the whole set, tracks which control each one satisfies, prompts you for the details only you know, and prints them as PDFs with your approver and review date on the front.

No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote A documented readiness position the audit firm can scope and price against Nothing. The audit firm prices your readiness, not your tooling

Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.