Trust pack download
Architecture summary, checklist, and questionnaire pre-fill for procurement binders.
Evidence for your control matrix
See what's built, what's not, and export audit proof yourself. SOC 2 Type II observation is in progress-we are not Type II certified.
Download the trust pack or open Shipped vs. Gap tables - then reproduce audit export in trial.
Architecture summary, checklist, and questionnaire pre-fill for procurement binders.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
The trust hub shows what Trustholm has shipped, what is still in backlog, and how to verify claims in your trial tenant.
Vendor origin: Trustholm is European Union (EEA) founder-led (Trustholm Pty Ltd, Australia). European founder-led vendor. EU/EEA contracting entity and VAT details are confirmed during enterprise onboarding. Contact security@trustholm.com for EU/EEA procurement (Central European Time (CET/CEST) for EU procurement and security reviews).
Start here: - Security and evidence - Shipped vs. Gap tables mapped to common audit controls - Tenant isolation - How MSP customer data stays separated - Audit and logging - Script execution export vs.
HTTP logs - Script signing - Signing policy before run - Trust downloads - Architecture summary, checklist, questionnaire pre-fill - Governance outcome stories - Anonymized composites for procurement (not named logos until legal approval)
What we do not claim: Vendor SOC 2 Type II (observation only), ISO 27001, IRAP, Essential Eight achievement for your estate, or other certifications. We supply technical artifacts for *your* control matrix - we do not automate your SOC 2 Trust Services Criteria like a GRC tool. You verify artifacts; your assessor owns certification outcomes.
Contact security@trustholm.com for the full trust pack during evaluation.
Privacy, legal agreements, security evidence, and self-serve trial verification.

Privacy policy, data handling, and DPA contact for procurement.

Terms of service, cookies policy, and enterprise contract schedules.

CIA mapping, Shipped/Gap evidence, operational FAQs, and procurement pack.

Export audit JSON/CSV yourself in under thirty minutes-self-serve proof vs gated vendor PDFs.
Security, isolation, audit, and data handling evidence pages.

Shipped capabilities and honest gaps for assessor review-privileged action audit, signing policy, tenant isolation, and rate limiting with explicit non-certification framing for enterprise and government diligence.

Schema-per-tenant PostgreSQL architecture, JWT tenant binding for portal users, agent polling credentials, and dedicated database profiles-with honest limits on application-layer defense for MSP SaaS procurement.

Security audit plane versus HTTP request logs, export APIs, tenant opt-out, correlation enrichment, and SIEM integration gaps stated honestly for SOC 2, ISM, and enterprise security questionnaire reviewers evaluating remote management evidence.

OIDC/SAML SSO, MFA flows, RBAC with module feature gates, JWT sessions, and Super Admin step-up-with customer IdP lifecycle responsibilities stated clearly.

PowerShell code signing policy enforcement, platform script catalog, built-in operation tags, audit attribution, and PKI deployment variations described without overclaiming HSM coverage or application-control certification.
No. We are not SOC 2 Type II certified. Observation is in progress. We publish Shipped vs Gap mapped to common audit controls so your security team can verify artifacts in trial - not a vendor attestation report.
Sign in to trial, open Security Center, export audit JSON or CSV, and inspect tenant settings. Each trust page lists the UI path or API endpoint to check.
Common gaps include WORM audit immutability and vendor SOC 2 Type II (observation in progress). Splunk/Datadog native sink templates remain backlog. Limitations blocks on each trust page name these explicitly.
AU is the primary launch region. EU home region is available for pilot and enterprise tenants. Exact residency for your contract is confirmed during onboarding - see /resources/digital-sovereignty-eu-msp-saas for EU buyers.
European founder-led with global operations via Trustholm Pty Ltd. EU/EEA contracting entity details are confirmed during enterprise onboarding.
Yes as technical reference material. We provide consumer responsibility framing without claiming IRAP or government vendor certification.