Compliance Coverage
A live, control-by-control map of how Trinitite's governance surfaces satisfy the requirements of EU AI Act, NIST AI RMF, ISO 42001, SOC 2, HIPAA, SEC/FINRA, NYDFS, and PCAOB — each control pinned to the signed evidence the platform produces for it.
What it is
Compliance Coverage is the bridge between what Trinitite does and what your framework requires. For each framework, it maps every relevant control to the governance surface that satisfies it and the signed artifact that proves it — so "how do you cover SOC 2 CC6.6?" is answered with "the Glass Box Ledger entry for every governed call, here is the verify bundle," not a paragraph of prose.
Why it matters
- From prose to proof. A control mapping that points at a signed artifact is materially different from one that points at a policy document. Compliance Coverage does the former.
- Live, not annual. The coverage map updates as your Guardian coverage widens — a control that was
partialbecomescoveredthe day you wire a new surface through a Guardian, and the attestation report reflects it. - Multi-framework. One evidence stream satisfies many frameworks; Coverage shows the crosswalk so you don't re-articulate the same proof five times.
- Procurement-ready. Hand a regulated buyer the coverage map during security review; each control links to its evidence.
How it works
- Map. Each framework control is linked to the Trinitite surface that satisfies it.
- Pin. Each link points at the signed artifact type the surface produces (ledger entry, attestation report, verify bundle).
- Roll up. Per-framework coverage status (
covered/partial/gap) aggregates from the underlying controls. - Refresh. Status updates as governance coverage widens and as Continuous Assurance events bump
gap→partial→covered.
Get started
- Read the Compliance Matrix for the full control-by-control mapping.
- Generate attestation reports via the Attestation & Compliance API.
- Track coverage status over time via Continuous Assurance.
→ Compliance Matrix — the control-by-control map. → Compliance Architecture — how evidence maps to frameworks. → Model Risk Management — the SR 11-7 / NIST AI RMF angle.