One pilot session
Install one agent, run one signed script, export the audit file. That is usually enough to answer the buy-or-not question.
Govern PowerShell with signing policy and exportable audit - so MSPs can answer assessors and insurers without RMM log archaeology.
Install one agent, run one signed script, and export the audit file - most teams do it in under thirty minutes.
No credit card · Pilot access within two business days · Enterprise reviewed manually

Most teams export their first audit file in under thirty minutes.
Install one agent, run one signed script, export the audit file. That is usually enough to answer the buy-or-not question.
Scripts, agents, trust evidence, and optional monitoring.

Scripts
Block unsigned scripts when policy requires it. Every run is recorded with who ran what on which machine.

Agents
Deploy a small agent that polls outbound. Search and target machines with catalog APIs built for large fleets.

Trust
Download what is built vs. not. Export audit rows from trial and attach them to your questionnaire.

Monitoring
Add SNMP ingest and NOC dashboards when your SKU includes the Monitoring module.
Three distinct outcomes - pilot fit, audit export, and fleet scale.
Run a pilot group before you mandate Trustholm fleet-wide.
Compare optionsExport who ran which signed script on which machine - without digging through RMM logs.
Review security evidenceServer-backed search and pagination - not full-fleet dropdowns.
See platform architectureDesign-partner MSPs and security reviewers validating script governance fit-not certification marketing.
“We reproduced a signed script run and CSV audit export in one pilot session-that export slice is what our cyber insurer actually asked for.”
Signing, four-eyes approval, and exportable audit-verify in a trial tenant. No SOC 2 badge claims; honest Shipped/Gap evidence for assessors.
Pick your jurisdiction hub for framework-specific evidence pages.

Essential Eight, IRAP/ISM consumer framing, and AU data residency.

NIST CSF / 800-53 consumer mapping and CMMC Level 2 enabler framing.

Cyber Essentials and NCSC-aligned remote access evidence.

GDPR processor framing, DORA ICT risk, NIS2 supply-chain evidence, and EU digital sovereignty for MSP script governance.
SOC 2 evidence framing applies across regions · Compare incumbent tools · Trust downloads
Public bundles from your operator catalog-or contact us for enterprise
We prove which signed scripts ran on which client machines. MSPs use Trustholm to enforce signing policy, run scripts with a clear record, and export audit files for assessors and cyber insurers.
We're built for script governance, not full endpoint management. If you need both, check our comparison pages to see if we're a fit.
We're not SOC 2 certified yet. We publish exactly what's built vs. not, mapped to common audit controls, so your security team can verify it themselves.
Most teams install one agent, run one signed script, and export audit rows in under thirty minutes. Fleet-scale rollouts use paginated catalog APIs -no loading every endpoint into a dropdown.
Launch region options and subprocessors are on the trust hub. Exact residency for your contract is confirmed during onboarding -not inferred from marketing copy.
A working audit export you can show your security reviewer or insurer -before you commit portfolio budget. If script evidence is your bottleneck, one pilot session usually answers the buy-or-not question.
What we do: Block unsigned scripts when your policy requires it. Record who ran what on which machine. Export that history for auditors and insurers -separate from RMM operational logs.
What we are not: We do not hold SOC 2, Essential Eight, CMMC, or other third-party certifications. See the trust hub for what is built vs. not.
Where to go next: Platform overview for modules and architecture. Compare how we fit beside NinjaOne, ConnectWise, and PDQ. Trust downloads for procurement packs. Start a trial on Govern (no credit card); Evidence and Enterprise tiers are reviewed within two business days.