{
  "version": "2026-07-13",
  "vendor": "Trustholm",
  "status": "observation_kickoff_not_type2",
  "sections": {
    "company_overview": {
      "product_description": "Multi-tenant MSP governance platform: signed PowerShell, audit export, tenant isolation, and agentic execution-intent gating beside incumbent RMMs.",
      "hosting": "Customer data in dedicated tenant schemas; platform metadata in system database.",
      "trust_hub": "https://www.trustholm.com/trust",
      "positioning": "Policy and evidence engine — not full RMM replacement; not L1 AI ticket bot."
    },
    "access_control": {
      "authentication": "JWT with tenant binding; optional MFA per tenant; SSO via SAML/OIDC.",
      "authorization": "Role and permission model; tenant.admin vs audit.export separation.",
      "privileged_access": "Super Admin support access audited; agent polling credentials per device.",
      "agentic_integration": "Tenant-scoped agentic integration API keys; external actor id required on execution-intent."
    },
    "logging_monitoring": {
      "audit_plane": "Append-only security audit events with optional integrity hashes.",
      "export": "Assessor package ZIP with manifest, CSV, trust artifact links; Govern vs Evidence caps via IEntitlementResolver.",
      "retention": "Configurable via COMPLIANCE_RETENTION_* SKUs.",
      "agentic_attestation": "AgenticExecution category records intent, approve, and attestation for external AI/automation runs."
    },
    "change_management": {
      "scripts": "Draft → approve → publish workflow; rules-first risk score at publish.",
      "platform_catalog": "Published platform scripts read-only until duplicated per tenant.",
      "ops_intelligence": "Beta MODULE_OPS_INTELLIGENCE priority queue; approved suggestions may submit execution-intent."
    },
    "business_continuity": {
      "backups": "Operator-managed per deployment guide; tenant schema migrations versioned.",
      "incident_response": "See DOCS/07-Compliance incident response templates."
    },
    "subprocessors": {
      "list_url": "https://www.trustholm.com/trust/subprocessors",
      "notes": "Stripe for billing; cloud provider per deployment."
    }
  }
}
