Govern trust & evidence

Shipped vs Gap for script orchestration

Govern trust for MSP script orchestration. See what's built, what's not, and export audit proof yourself in trial. We do not hold SOC 2 Type I or Type II. We do not claim an observation period on this site.

Verify it yourself

Download the trust pack or open Shipped vs. Gap tables. Then reproduce audit export in trial.

ZIPdownload bundle

Trust pack download

Architecture summary, checklist, and questionnaire pre-fill for procurement binders.

Download trust pack

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

This is the Govern evidence surface on www. Tables cover script signing, tenant isolation, and audit export. Company legal and subprocessors stay on the company trust hub. For Migrate, ShareSight, and Bridge, start from each product page and request access from that product's trial page (/migrate/trial, /sharesight/trial, /bridge/trial).

What Govern has shipped vs backlog, and how to verify claims in a Govern trial tenant:

Vendor origin: Trustholm is European Union (EEA) founder-led (Trustholm, Australia). European founder-led vendor. EU/EEA contracting entity and VAT details are confirmed during enterprise onboarding. Contact security@trustholm.com for EU/EEA procurement (Central European Time (CET/CEST) for EU procurement and security reviews).

Start here: - Security and evidence: Shipped vs. Gap tables mapped to common audit controls - Tenant isolation: How MSP customer data stays separated - Audit and logging: Script execution export vs.

HTTP logs - Script signing: Signing policy before run - Trust downloads: Architecture summary, checklist, questionnaire pre-fill - Governance outcome stories: Anonymized composites for procurement (not named logos until legal approval)

What we do not claim: Vendor SOC 2 Type I or Type II, ISO 27001, IRAP, Essential Eight achievement for your estate, or other certifications. We supply technical artifacts for *your* control matrix. We do not automate your SOC 2 Trust Services Criteria like a GRC tool. You verify artifacts; your assessor owns certification outcomes.

Contact security@trustholm.com for the full trust pack during evaluation.

Trust Centre

Privacy, legal agreements, security evidence, and self-serve trial verification.

Procurement artifacts

Frequently asked questions

Does Trustholm provide a SOC 2 report?

No. We do not hold SOC 2 Type I or Type II. We do not claim an observation period on this site. We publish Shipped vs Gap and trial export so your assessor can verify artifacts.

How do I verify claims in a trial tenant?

Sign in to trial, open Security Center, export audit JSON or CSV, and inspect tenant settings. Each trust page lists the UI path or API endpoint to check.

What gaps should I document in our SSP?

Common gaps include WORM audit immutability and vendor SOC 2 (we do not hold Type I or Type II). Splunk/Datadog native sink templates remain backlog. Limitations blocks on each trust page name these explicitly.

Is data hosted in Australia?

AU is the primary launch region. EU home region is available for pilot and enterprise tenants. Exact residency for your contract is confirmed during onboarding. See /govern/resources/digital-sovereignty-eu-msp-saas for EU buyers.

Is Trustholm a European vendor?

European founder-led. EU/EEA contracting entity details are confirmed during enterprise onboarding.

Can we use this hub for government procurement?

Yes as technical reference material. We provide consumer responsibility framing without claiming IRAP or government vendor certification.