TRUST CENTER · CONTROL CATALOG
Control assertions connected to inspectable evidence.
The catalog identifies the current control objective, implementation state, evidence class, owner, and limitation. It supports review without implying an external audit opinion.
Assurance limitation
No entry in this catalog represents SOC, ISO, PCI, government, provider, or other independent certification. External service names in the console are integration registry labels, not endorsements or verified affiliations.
Control domains
| ID | Objective | Implementation evidence | State |
|---|---|---|---|
| BOT-01 | Credential verification requires a valid browser-abuse challenge | Turnstile widget, Siteverify response checks, denial tests | Implemented |
| IAM-01 | Credentials are verified outside the browser | Server verifier; browser bundle inspection | Implemented |
| IAM-02 | Privileged access requires a second factor | Challenge route and integration test | Implemented |
| SES-01 | Session tokens are host-bound and opaque | Set-Cookie response; session schema | Implemented |
| SES-02 | Inactive and excess sessions are revoked | Idle and concurrency regression tests | Implemented |
| AUTH-01 | Mutation requires role and CSRF authority | API denial tests and audit outcomes | Implemented |
| APP-01 | Input and methods fail through structured contracts | Validation and method regression tests | Implemented |
| APP-02 | Browser capabilities and content origins are restricted | Live CSP and security headers | Implemented |
| INF-01 | Application services are not public listeners | Host socket inventory | Implemented |
| INF-02 | Application process has minimal host authority | System service sandbox definition | Implemented |
| DAT-01 | Sensitive control records are minimized | Schema and API response inspection | Implemented |
| AUD-01 | Consequential actions are correlated | Audit table and request-ID response | Implemented |
| VUL-01 | Known dependency findings are reviewed before release | Dependency audit result | Implemented |
| IR-01 | Security events follow a defined lifecycle | Incident response standard and runbooks | Documented |
| BCM-01 | Releases have a recoverable pre-change state | Backup digest and rollback procedure | Implemented |
Evidence classes
- Configuration
- Version-controlled service, origin, header, and deployment definitions.
- Automated test
- Repeatable API, build, link, dependency, and packaging checks.
- Live observation
- Response headers, status codes, process state, interface state, and socket ownership.
- Operational record
- Release tag, change record, audit event, backup digest, and incident timeline.
- Policy
- Approved responsibilities, decision rules, retention periods, and review cadence.
Review and exceptions
Control owners review the catalog quarterly and after material security or architecture change. A limitation or exception records the affected control, reason, risk, compensating measure, owner, approval, expiry, and closure evidence. Expired exceptions are not silently treated as accepted state.
Operational