Security for Government & Regulated Buyers
ISM/PSPF consumer-responsibility framing, trial-verifiable evidence, and honest non-certification positioning for AU government procurement.
Govern privileged automation with signing, separation of duties, and exportable audit-beside your RMM, verifiable in a trial tenant.
Trustholm does not claim IRAP, ISM certification, or government vendor badges. We provide technical reference material and trial-verifiable artifacts for your system security plan.
ISM / PSPF alignment: Pair security audit export, MFA, tenant isolation, and signing policy with your agency's SSP, IR plan, and pentest evidence. See AU compliance hub and downloadable ISM vendor pack.
Consumer responsibilities: Network controls, IdP lifecycle, endpoint hardening, and immutable log storage remain yours. Document WORM audit gap and compensating controls (restricted DBA, frequent export to customer-controlled storage).
Procurement: Use trust hub Shipped/Gap tables in RFP responses. Reproduce export in trial during assessor walkthroughs-timestamped evidence beats slide decks.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
Key capabilities
- Schema-per-tenant data separation architecture
- Security audit export with category/datetime filters
- Dual-custody script approval (four-eyes default)
- AU ISM vendor pack download
- No IRAP or Essential Eight product certification claims
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| Just-in-time privilege elevation | Settings → Security JIT policy + grant queue; audit PrivilegeElevation / jit.privilege.*; Assessor Package can include elevation lifecycle | Shipped | Default off; Phase 2 packages, settings/agent/user gates, eligible roles, justification and break-glass policies shipped |
| Privileged actions audit | Web Audit logs (/audit); GET /api/audit, export JSON/CSV | Shipped | - |
| Audit immutability | Append-only rows in normal application flows; per-tenant integrity hash chain with Security Centre verify/repair | Partial | Database operators can still mutate tables. Product WORM storage remains backlog; operator-side Object Lock archive handoff is available. Hash-chain verification is shipped. |
| Tenant isolation | Schema-per-tenant PostgreSQL; JWT tenant binding on API | Shipped | - |
| Dual-custody (four-eyes) | Settings → Security toggle; Script Management blocks submitter self-approve | Shipped | On by default; ERR_DUAL_CUSTODY_VIOLATION and script.dual_custody.denied in audit |
Frequently asked questions
- Is Trustholm IRAP assessed?
No. Isolation and audit architecture are inputs to your SSP-not a product checkbox. Pair with agency-specific consumer responsibilities.
- Can we use this hub in government procurement?
Yes as technical reference. Contact security@trustholm.com for full trust pack and DPA during evaluation.