Architecture and threats
Control plane, execution plane, egress boundary, containment, and forensic plane.
Read the architecture →Trust center
TrustRail separates repository-verifiable controls from deployment evidence and external assurance. “Not measured” and “not certified” are states, not zeros.
| Area | Status | Evidence boundary |
|---|---|---|
| Security architecture | Published | Thirty invariants, threat boundaries, and evidence links |
| OIDC + bound JIT | Implemented | Production requires an organization binding; JIT cannot grant owner |
| SCIM deprovisioning | Implemented | Membership suspension, browser-session revocation, and transactional audit |
| Audit evidence | Implemented | Hash-chained NDJSON export and an offline verifier |
| CSV/PDF reporting | Implemented | One normalized snapshot with explicit NOT_MEASURED values |
| SOC 2 Type I / II | Not certified | Requires an independent auditor opinion |
| ISO/IEC 27001 / 42001 | Roadmap | No certification badge or claim |
| External penetration test | Not yet evidenced | Internal adversarial tests are not called independent |
Control plane, execution plane, egress boundary, containment, and forensic plane.
Read the architecture →Commands, manifests, and explicit external validation gates.
Open the evidence register →The properties the implementation and database are required to preserve.
Review all thirty →What TrustRail does not replace, observe, certify, or promise.
Read the limitations →Report suspected vulnerabilities through the private security contact in the deployment or support agreement; do not place unpatched details in a public issue. TrustRail ships a disclosure policy and a technical incident-response runbook, but no bounty or independent response-time certification is implied.
Customer incidents preserve evidence first, restrict authority automatically, and require human-reviewed recovery. The forensic plane recommends; it cannot execute containment.