TRUST CENTER · CONTROL CATALOG

Control assertions connected to inspectable evidence.

The catalog identifies the current control objective, implementation state, evidence class, owner, and limitation. It supports review without implying an external audit opinion.

Owner
Security Assurance
Baseline
1.4
Reviewed
05 Aug 2026
Assurance
Internal evidence
Assurance limitation

No entry in this catalog represents SOC, ISO, PCI, government, provider, or other independent certification. External service names in the console are integration registry labels, not endorsements or verified affiliations.

Control domains

IDObjectiveImplementation evidenceState
BOT-01Credential verification requires a valid browser-abuse challengeTurnstile widget, Siteverify response checks, denial testsImplemented
IAM-01Credentials are verified outside the browserServer verifier; browser bundle inspectionImplemented
IAM-02Privileged access requires a second factorChallenge route and integration testImplemented
SES-01Session tokens are host-bound and opaqueSet-Cookie response; session schemaImplemented
SES-02Inactive and excess sessions are revokedIdle and concurrency regression testsImplemented
AUTH-01Mutation requires role and CSRF authorityAPI denial tests and audit outcomesImplemented
APP-01Input and methods fail through structured contractsValidation and method regression testsImplemented
APP-02Browser capabilities and content origins are restrictedLive CSP and security headersImplemented
INF-01Application services are not public listenersHost socket inventoryImplemented
INF-02Application process has minimal host authoritySystem service sandbox definitionImplemented
DAT-01Sensitive control records are minimizedSchema and API response inspectionImplemented
AUD-01Consequential actions are correlatedAudit table and request-ID responseImplemented
VUL-01Known dependency findings are reviewed before releaseDependency audit resultImplemented
IR-01Security events follow a defined lifecycleIncident response standard and runbooksDocumented
BCM-01Releases have a recoverable pre-change stateBackup digest and rollback procedureImplemented

Evidence classes

Configuration
Version-controlled service, origin, header, and deployment definitions.
Automated test
Repeatable API, build, link, dependency, and packaging checks.
Live observation
Response headers, status codes, process state, interface state, and socket ownership.
Operational record
Release tag, change record, audit event, backup digest, and incident timeline.
Policy
Approved responsibilities, decision rules, retention periods, and review cadence.

Review and exceptions

Control owners review the catalog quarterly and after material security or architecture change. A limitation or exception records the affected control, reason, risk, compensating measure, owner, approval, expiry, and closure evidence. Expired exceptions are not silently treated as accepted state.