
Compliance framing
IRAP Readiness Framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
Australian government buyer responsibility matrix for SaaS consumers.
Trustholm provides IAM evidence mapping and audit exports; consumers supply SSP, IR, and assessment artifacts.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
IRAP and ISM assessments evaluate systems in context. As a SaaS consumer, your agency or customer supplies the System Security Plan, incident response evidence, penetration test results, governance artifacts, and classification-appropriate control narratives.
Trustholm supplies technical evidence: IAM mapping, audit export APIs, tenant isolation architecture documentation, subprocessors list on our trust hub, and downloadable trust pack materials for vendor due diligence.
Vendor vs consumer matrix: Trustholm operates the application and database layers-portal authentication flows, script orchestration, security audit recording, and schema-per-tenant data separation in PostgreSQL.
Customers configure SSO with their identity provider, lifecycle users and roles, define script signing and approval policies, operate endpoints and agents, execute incident response on their side of the shared responsibility model, and maintain SSP content that reflects their deployment choices.
ISM themes commonly mapped: Identification and authentication align with JWT tenant binding, MFA options, and agent polling credentials. Event logging and monitoring align with security audit export-not HTTP operational logs alone.
System hardening and software development lifecycle evidence for your boundary include Trustholm architecture diagrams and honest gap tables; they do not replace agency penetration testing or IR exercise records you maintain.
Data residency and subprocessors: Australian region options for launch are documented in hosting materials available via trust pack download. Subprocessors appear at /trust/subprocessors with update notification terms for paid customers. Enterprise buyers request data residency tables and network architecture references during trial via security@trustholm.com.
MSP serving government clients: Include Trustholm vendor evidence in your customer’s SSP appendices. Your customer remains accountable to their agency assessor; Trustholm does not substitute for consumer-side IRAP assessment outcomes. Pair IAM and audit export screenshots with your customer’s governance, change management, and endpoint security programs.
What we do not claim: IRAP certification of Trustholm as a vendor product unless an assessment is completed and published on the trust hub. Agency-specific controls vary by classification and system boundary-mapping is customer-specific with our artifacts as supporting inputs, not definitive compliance statements.
Engage security@trustholm.com during trial for ISM-oriented mapping discussions scoped to your deployment. Use this page to frame honest consumer versus provider responsibilities, not certification marketing. Request the trust pack for subprocessors, hosting region detail, and architecture diagrams suitable for agency vendor review.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| IAM evidence mapping | IRAP-style IAM documentation in product compliance docs | Shipped | - |
| Consumer responsibilities | Customer SSP, IR plan, and pentest evidence required | Partial | - |
| IRAP assessment of vendor | Not claimed unless/until completed | Gap | - |
We do not claim IRAP certification. We provide evidence mapping and architecture documentation for consumer assessments.
Provider: application security features, tenant isolation architecture, audit APIs. Consumer: SSP, user lifecycle, endpoint security, IR testing, governance.
AU region options are documented in trust materials. Request the data residency table via /trust/downloads or security@trustholm.com.
Published list at /trust/subprocessors. Updates notified per contractual terms for paid customers.
IAM and logging evidence maps to common ISM themes in our trust pack. Full mapping is customer-specific-engage security@trustholm.com during trial.
Include Trustholm vendor evidence in your customer SSP appendices. Your customer remains accountable to their agency assessor.