Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Auditor Evidence Request Simulator

An audit is not a review of your policies. It is a series of requests to prove that a control actually ran, on dates inside the observation window. Pick your framework, mark what you could produce this week, and see what an auditor would come back on.

1. Which report are you going for?

The request list changes with the framework.

2. Your observation window

A Type II opinion covers a period, so evidence has to exist across it.

Controls have been running for

3. Mark what you could produce this week

Be honest. The point of a rehearsal is to find this now rather than during fieldwork.

Your evidence readiness

Answer the requests to see where you stand.

--
Not started

Nothing marked yet.

A rehearsal with representative requests. Your auditor will send their own list and sample across the window, so one control can generate several requests. Want someone to run the auditor relationship for you? See Auditor Management & Advocacy.

Questions

What is an evidence request?

It is the auditor asking you to prove a control ran. Not that a policy exists, but that the thing the policy describes actually happened during the observation window, with dated artefacts such as a ticket, a log export, an approval, or a signed acknowledgement.

How many requests should I expect?

It varies by framework and scope. A first SOC 2 Type II commonly runs to well over a hundred individual requests once sampling is applied, because the auditor will ask for several instances of the same control across the window rather than one example.

Why does the observation window matter so much?

A Type II opinion covers a period, so evidence has to exist across that period. A control you implemented last week cannot produce three months of history. This is the single most common reason a readiness project slips: the window was chosen after the work started rather than before. Our SOC 2 readiness work sets the window first for exactly this reason.

Can I negotiate what counts as evidence?

To a degree, yes. Scope, sampling sizes, and which artefact satisfies a request are all discussed with the auditor rather than dictated. Teams who treat the auditor as a counterparty rather than an examiner generally have a smoother engagement.

Is this tool free?

Yes, free and no signup. It is a rehearsal, not an audit, and the request list is representative rather than the exact list any given firm will send.

Before you go

Want your gap list by email?

I send a few short notes on getting through an audit: what auditors actually accept as evidence, and where the time goes. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

Auditor Management and Advocacy

We handle the auditor relationship and the evidence requests so your team can keep working.

Explore Auditor Management and Advocacy →

Let somebody else handle the auditor.

We manage the relationship, work the request list, gather the evidence, and push back where something falls outside the agreed scope.

See Auditor Management Book a call

Want the full picture?

This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

Start your free assessment See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.