IRAP Readiness Framing

Australian government buyer responsibility matrix for SaaS consumers.

Trustholm provides IAM evidence mapping and audit exports; consumers supply SSP, IR, and assessment artifacts.

IRAP Readiness Framing

Framework evidence framing before detailed tables below.

Compliance reviewer examining governance documents with laptop

Compliance framing

IRAP Readiness Framing

Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.

  • Reproduce audit export in trial
  • Download trust pack for binders
  • Regional hub cross-links
Gaprows published openly
Download trust pack

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

IRAP and ISM assessments evaluate systems in context. As a SaaS consumer, your agency or customer supplies the System Security Plan, incident response evidence, penetration test results, governance artifacts, and classification-appropriate control narratives.

Trustholm supplies technical evidence: IAM mapping, audit export APIs, tenant isolation architecture documentation, subprocessors list on our trust hub, and downloadable trust pack materials for vendor due diligence.

Vendor vs consumer matrix: Trustholm operates the application and database layers-portal authentication flows, script orchestration, security audit recording, and schema-per-tenant data separation in PostgreSQL.

Customers configure SSO with their identity provider, lifecycle users and roles, define script signing and approval policies, operate endpoints and agents, execute incident response on their side of the shared responsibility model, and maintain SSP content that reflects their deployment choices.

ISM themes commonly mapped: Identification and authentication align with JWT tenant binding, MFA options, and agent polling credentials. Event logging and monitoring align with security audit export-not HTTP operational logs alone.

System hardening and software development lifecycle evidence for your boundary include Trustholm architecture diagrams and honest gap tables; they do not replace agency penetration testing or IR exercise records you maintain.

Data residency and subprocessors: Australian region options for launch are documented in hosting materials available via trust pack download. Subprocessors appear at /trust/subprocessors with update notification terms for paid customers. Enterprise buyers request data residency tables and network architecture references during trial via security@trustholm.com.

MSP serving government clients: Include Trustholm vendor evidence in your customer’s SSP appendices. Your customer remains accountable to their agency assessor; Trustholm does not substitute for consumer-side IRAP assessment outcomes. Pair IAM and audit export screenshots with your customer’s governance, change management, and endpoint security programs.

What we do not claim: IRAP certification of Trustholm as a vendor product unless an assessment is completed and published on the trust hub. Agency-specific controls vary by classification and system boundary-mapping is customer-specific with our artifacts as supporting inputs, not definitive compliance statements.

Engage security@trustholm.com during trial for ISM-oriented mapping discussions scoped to your deployment. Use this page to frame honest consumer versus provider responsibilities, not certification marketing. Request the trust pack for subprocessors, hosting region detail, and architecture diagrams suitable for agency vendor review.

TopicEvidenceStatusNotes
IAM evidence mappingIRAP-style IAM documentation in product compliance docsShipped-
Consumer responsibilitiesCustomer SSP, IR plan, and pentest evidence requiredPartial-
IRAP assessment of vendorNot claimed unless/until completedGap-

Frequently asked questions

Has Trustholm completed IRAP assessment as a vendor?

We do not claim IRAP certification. We provide evidence mapping and architecture documentation for consumer assessments.

What is the consumer vs provider split?

Provider: application security features, tenant isolation architecture, audit APIs. Consumer: SSP, user lifecycle, endpoint security, IR testing, governance.

Where is data hosted?

AU region options are documented in trust materials. Request the data residency table via /trust/downloads or security@trustholm.com.

Who are subprocessors?

Published list at /trust/subprocessors. Updates notified per contractual terms for paid customers.

Can we get ISM control mapping?

IAM and logging evidence maps to common ISM themes in our trust pack. Full mapping is customer-specific-engage security@trustholm.com during trial.

How do MSPs serving gov clients use this?

Include Trustholm vendor evidence in your customer SSP appendices. Your customer remains accountable to their agency assessor.