
Compliance framing
SOC 2 Evidence Framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
Trust Services Criteria themes mapped to product artifacts for assessor review.
Trustholm helps customers evidence CC6/CC7 controls via audit export and IAM features-we do not claim SOC 2 certification.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
SOC 2 evaluations use Trust Services Criteria themes. Trustholm customers commonly map CC6 (logical access) to portal IAM: users and roles UI, JWT sessions, MFA flows, and security audit entries for administrator actions.
CC7 (system operations) pairs exportable audit data with your operator monitoring of infrastructure-rate limiting, health checks, and incident response runbooks you maintain as the cloud consumer.
CC6 in product terms: Portal administrators manage users and roles within tenant scope. JWT sessions bind authenticated principals to a resolved tenant; mismatches return forbidden responses rather than silent cross-tenant access.
MFA flows apply to privileged portal operations where configured. Security audit categories capture administrator actions-user lifecycle, role changes, script publish and approve events, policy updates-separate from HTTP request logs enriched for operational chargeback.
CC7 in product terms: Exportable audit data supports assessor windows with datetime and category filters within documented row caps. Super Admin operators observe distributed rate limiting and platform health signals; your team owns infrastructure monitoring, backup verification, and incident response execution in your deployment model.
Trustholm documents subprocessors, hosting regions, and architecture references on the trust hub for vendor due diligence packets.
What we provide: JSON/CSV audit export with category and datetime filters, Security Center checklist deep links, distributed rate limit observability for Super Admin operators, IAM mapping tables in the trust pack, and honest Shipped versus Gap evidence rows aligned to common CC6/CC7 interview questions.
What we do not provide: A vendor SOC 2 Type II report, bridge letter template, or certification badge unless explicitly published in a future trust update.
How MSPs use this page: Include exported audit slices, IAM screenshots, and our evidence table in your customer-facing SOC 2 vendor appendix. Your assessor validates control design and operating effectiveness in your environment and system boundary-Trustholm is one subprocess among many.
vCISOs pair our artifacts with pentest results, vulnerability management evidence, and customer-operated controls outside the product.
Gap honesty: Hash-chain audit immutability and native SIEM connectors remain backlog items documented on trust pages. Do not imply WORM storage or Sentinel integration ships today. When questionnaire authors ask for certification slogans, redirect them to technical artifacts and your program ownership statement.
Use this page as evidence framing in your vendor packet-not as proof that Trustholm holds third-party SOC 2 certification. Your organization owns SOC 2 program outcomes if pursued.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| CC6 logical access | Users/roles UI, JWT sessions, admin action audit | Shipped | - |
| CC7 system operations | Audit log, monitoring modules, distributed rate limits | Shipped | Pair with operator infra monitoring |
| Vendor SOC 2 Type II | Not claimed-provide evidence artifacts for customer assessments | Gap | - |
No-we provide evidence artifacts-audit export, IAM features, Security Center checklist-for your assessor. Your organization owns SOC 2 program outcomes and certification if pursued.
CC6 logical access maps to users/roles, JWT, MFA, and admin action audit. CC7 system operations maps to audit export plus your infrastructure monitoring. Exact mapping depends on your system boundary.
Yes. Tenant administrators with appropriate permissions can export JSON/CSV from the audit API within server row caps. Store exports in your GRC tool with retention matching policy.
Contact security@trustholm.com during trial for trust pack materials. Formal bridge letters depend on commercial relationship stage.
Document backlog items honestly: hash-chain audit immutability, native Sentinel connector, and any customer-operated controls outside the product boundary.
Many ISO 27001 Annex A controls overlap CC6/CC7 themes. Use the same evidence tables; we do not claim ISO certification on marketing pages.