Skip to main content
TrustOps
Trust center

Trust assurance center

Package the same evaluated posture for internal operators, auditors, and customer reviewers without leaking private evidence by default. Shares are scoped, expiring, revocable, and backed by hashed assessment state.

tenant_internal

Internal command

Security, GRC, platform, and AI owners

Private evidence, owners, remediation notes, workflows.
posture_full

Auditor review

External auditors and assessors

Read-only posture, evidence summaries, hashes, snapshots.
public_summary

Customer trust

Prospects, customers, and partner reviewers

Public summary, readiness status, approved artifacts.

Issue a new share

Auditor role · scope posture_full. Token expires automatically; shared data is capped at public summary by default and can be revoked below at any time.

Access and data boundaries

Recommended default: require auth in server mode, resolve every request to one tenant, gate actions by role, and share externally through expiring auditor tokens.

Admin
Users, keys, connectors, workflows, snapshots, and controls.
Security admin
Operate evidence sources, workflows, snapshots, and controls.
Contributor
Triage, evidence requests, and approved workflow runs.
Read only
Internal posture and evidence visibility without mutation.
Auditor share
External read-only review with owners and notes redacted.

0 active shares

Revoking a share appends a revocation record; future probes with that token fail and the share drops from this list.

No active shares. Issue one above to start.