Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Trust Center Builder

Most security questionnaires ask the same forty things. A public trust page answers them once, in the open, so a reviewer can get what they need without your team writing it out again. Mark what you could publish today and see how far it gets you.

1. Your company

Optional. Only used to title the outline.

2. What could you publish today?

Only tick what is true right now. A trust page that overstates gets found out during diligence, which is worse than having no page.

Diligence answered up front

Tick what you can publish to see your coverage.

--
Nothing selected

Tick items on the left to build your outline.

The coverage figure is a rough estimate of how much of a typical security review your page answers. Keep it accurate and add a review date. Want it built and kept current for you? See our Trust Center, or questionnaire help for the forms that still arrive.

Questions

What is a trust center?

A public page that answers the security questions buyers ask, before they ask them. It typically covers your certifications, how you handle data, where it is stored, your subprocessors, and how to report a vulnerability or reach a human about security.

Does a trust page really reduce questionnaires?

It rarely removes them entirely, but it shortens them. A reviewer who can find your encryption, retention, subprocessor and certification answers online tends to send a narrower list, and it moves the conversation forward while your team is asleep.

Should I publish my SOC 2 report on it?

Publish that the report exists, along with its type, scope and period. The report itself is normally shared under NDA rather than posted publicly, so the usual pattern is a request form on the page that routes to whoever handles diligence. If you do not have one yet, SOC 2 readiness is where we start.

What if I do not have a certification yet?

A trust page still helps. Being clear about what you do today, and honest about what is in progress with a date, is more useful to a reviewer than silence. Do not imply a certification you do not hold, because that surfaces quickly and badly during diligence.

Is this tool free?

Yes, free and no signup. It produces an outline and a coverage estimate, not a hosted page.

Before you go

Want your outline by email?

I send a few short notes on getting through buyer security reviews faster, including what reviewers actually look for. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

Trust Center

Built from your compliance workspace and kept current automatically.

Explore Trust Center →

Answer it once, in public.

We build the trust page, write the answers so they hold up under review, and handle the questionnaires that still come in.

See Trust Center Setup Book a call

Want the full picture on your vendors?

This gives you the shape of the problem. traztech Workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.

Start your free vendor assessment See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.