Trust & Evidence Center
Transparent compliance mapping showing how Vallum capabilities relate to enterprise security frameworks. Each mapping includes the support status, evidence Vallum can produce, limitations, customer responsibilities, and external controls required.
Positioning: Vallum is independent proof-grade trust infrastructure for scoped authorization, evidence verification, cryptographic provenance, certification, public verification, and defensible evidence delivery. Vallum integrates with existing systems. It does not require Wayne OS and does not replace identity management, endpoint protection, network security, cloud security, governance, or legal review.
Important: Vallum may produce evidence relevant to the control objectives listed below. Additional organizational, technical, legal, and operational controls may be required. Vallum does not satisfy, guarantee compliance with, make customers compliant with, or claim regulator approval for any framework listed. Compliance is an organizational responsibility that requires comprehensive controls beyond any single product.
Our Trust Principles
Transparency by Default
Every claim on this page includes the support status, limitations, and customer responsibilities. We do not obscure what Vallum does not do.
No Security Theater
We distinguish between evidence Vallum can produce and compliance guarantees (which require comprehensive organizational controls beyond any single product).
Auditor-Friendly Design
Evidence packages are designed to be shared with auditors directly. They are self-contained and independently verifiable without requiring access to Vallum systems.
Honest Boundaries
Vallum is technical infrastructure. It is not legal advice, it is not a compliance certification, and it does not replace human judgment, organizational policies, or comprehensive security programs.
Compliance Mapping
CC6.1Logical and Physical Access ControlsSupported EvidenceEvidence Vallum Can Provide
Titan Handshake produces authorization receipts for every protected operation. Receipts document the identity, tenant, operation type, policies evaluated, and authorization decision. These receipts can be assembled into evidence packages for auditor review.
Limitations
Vallum only produces evidence for operations routed through Titan Handshake. Access controls for systems outside Vallum (network, physical, endpoint) are not covered. Vallum does not enforce physical access controls.
Customer Responsibilities
Integrate all auditable operations with Titan Handshake. Maintain physical and network access controls independently. Ensure identity provider integration is correctly configured.
External Controls Required
Identity provider (IdP), network access controls, physical security, endpoint protection
CC7.2System Monitoring and Anomaly DetectionPartial Technical SupportEvidence Vallum Can Provide
Titan Handshake receipts create an immutable record of authorization decisions. Titan Verify assembles these into evidence packages. Denial receipts document blocked operations. These records support monitoring and anomaly detection workflows.
Limitations
Vallum does not perform anomaly detection itself. It produces evidence that can feed into monitoring systems, but does not replace SIEM, alerting, or incident response tooling. Real-time alerting is outside Vallum's scope.
Customer Responsibilities
Implement SIEM or log aggregation. Configure alerting rules. Establish incident response procedures. Route Vallum receipts to monitoring infrastructure.
External Controls Required
SIEM platform, alerting system, incident response procedures, log aggregation
CC8.1Change ManagementPartial Technical SupportEvidence Vallum Can Provide
Operations that modify system configuration can be gated through Titan Handshake, producing authorization receipts that document who approved the change, when, and under what policy. Evidence packages can document the change lifecycle.
Limitations
Vallum does not enforce change management processes. It can receipt authorization decisions for changes routed through it, but does not manage change request workflows, approval chains, or rollback procedures.
Customer Responsibilities
Implement change management workflows. Route change approvals through Titan Handshake. Maintain change advisory board processes. Document rollback procedures.
External Controls Required
Change management system, approval workflows, version control, deployment pipelines
A.8.3Information Access RestrictionSupported EvidenceEvidence Vallum Can Provide
Titan Handshake enforces tenant-scoped authorization for protected operations. Wrong-tenant access fails closed. Private evidence within Verified Ops is tenant-isolated. Authorization receipts document every access decision.
Limitations
Vallum enforces access restriction only for operations routed through Titan Handshake and data within Verified Ops. Application databases, file systems, and third-party services require their own access controls. Vallum does not replace database-level or filesystem-level access restrictions.
Customer Responsibilities
Implement access controls for all data stores. Route sensitive operations through Titan Handshake. Maintain role-based access policies. Conduct regular access reviews.
External Controls Required
Database access controls, filesystem permissions, application-level authorization, role management system
A.12.4.1Event LoggingSupported EvidenceEvidence Vallum Can Provide
Titan Handshake generates immutable receipts for every protected operation. Titan Verify assembles receipts into evidence packages with manifests. Titan Sign provides cryptographic sealing. These records form a tamper-evident event log for Vallum-protected operations.
Limitations
Vallum only logs events for operations routed through its infrastructure. Application events, system events, network events, and user activity outside Vallum are not captured. Vallum does not replace centralized logging or SIEM.
Customer Responsibilities
Implement centralized logging for all systems. Route auditable operations through Titan Handshake. Maintain log retention policies. Protect log integrity.
External Controls Required
Centralized logging platform, SIEM, log retention policies, log integrity protection
Article 25Data Protection by Design and DefaultPartial Technical SupportEvidence Vallum Can Provide
Tenant-scoped evidence boundaries limit data exposure. Public verification endpoints expose only minimal safe status. Private evidence is tenant-isolated. Authorization receipts document data access decisions.
Limitations
Vallum does not implement data minimization for your application data. It does not control what data your application collects, processes, or retains. Data protection by design must be implemented across your entire data lifecycle, not just within Vallum-protected operations.
Customer Responsibilities
Implement data minimization in application design. Conduct Data Protection Impact Assessments. Maintain privacy-by-design documentation. Implement data retention policies.
External Controls Required
Privacy engineering practices, DPIA process, data classification, retention management, consent management
Article 32Security of ProcessingPartial Technical SupportEvidence Vallum Can Provide
Tenant isolation within Verified Ops, immutable audit trails for protected operations, and cryptographic sealing of evidence packages contribute to security of processing for Vallum-managed operations.
Limitations
Vallum provides security measures for its own infrastructure only. Security of processing across your entire data estate requires comprehensive controls beyond Vallum. Vallum does not encrypt data at rest in your databases, protect your network perimeter, or manage your endpoint security.
Customer Responsibilities
Implement encryption at rest and in transit. Maintain network security. Conduct regular security assessments. Implement incident response procedures.
External Controls Required
Encryption (at rest and in transit), network security, vulnerability management, incident response, security monitoring
Article 14Human OversightIntegration RequiredEvidence Vallum Can Provide
Titan Handshake can gate operations that require human approval, producing receipts that document whether human oversight was obtained. Evidence packages can demonstrate that human review occurred before critical operations.
Limitations
Vallum does not implement human oversight interfaces. It can receipt that a human approved an operation (if your workflow routes approvals through Titan Handshake), but it does not provide the UI, notification system, or escalation workflow for human review. Human oversight design is an application-layer responsibility.
Customer Responsibilities
Design human oversight workflows. Implement approval interfaces. Define which operations require human review. Route approval decisions through Titan Handshake for evidence.
External Controls Required
Human review interfaces, escalation workflows, notification systems, role-based approval chains, override mechanisms
Article 15Accuracy, Robustness, and CybersecurityPartial Technical SupportEvidence Vallum Can Provide
Titan Handshake can receipt authorization decisions that gate AI operations, creating evidence of what was permitted. Fail-closed behavior means unauthorized operations are denied. Evidence packages document the operational boundary.
Limitations
Vallum does not make AI models more accurate or robust. It does not validate model outputs, test model performance, or prevent model degradation. Accuracy and robustness are model-layer and application-layer concerns. Vallum provides authorization and evidence infrastructure, not model quality assurance.
Customer Responsibilities
Implement model testing and validation. Monitor model performance. Maintain cybersecurity controls. Conduct adversarial testing. Document accuracy metrics.
External Controls Required
Model testing frameworks, performance monitoring, adversarial testing, cybersecurity controls, accuracy benchmarking
§164.312(b)Audit ControlsSupported EvidenceEvidence Vallum Can Provide
Immutable authorization receipts for protected operations, evidence packages with complete receipt chains, cryptographically sealed audit records via Titan Sign. These records can support audit control requirements for operations routed through Vallum.
Limitations
Vallum only produces audit records for operations routed through Titan Handshake. PHI access through systems outside Vallum is not captured. Vallum does not replace EHR audit logging, database access logging, or application-level audit trails. Complete HIPAA audit coverage requires controls across all systems touching PHI.
Customer Responsibilities
Implement audit logging across all PHI-touching systems. Route sensitive operations through Titan Handshake. Maintain audit log retention per HIPAA requirements. Conduct regular audit log reviews.
External Controls Required
EHR audit logging, database audit trails, application logging, log retention system, regular audit reviews
Request an Auditor Pack
We can prepare a detailed document covering our architectural security evidence, control mappings, and evidence generation capabilities for your specific audit requirements. This is prepared on request — not a pre-built download.
Legal Boundary Notice
This page provides technical information about Vallum capabilities and how they may relate to compliance framework requirements. It is not legal advice. It is not a compliance certification. It does not guarantee that using Vallum will make your organization compliant with any framework. Compliance is an organizational responsibility that requires comprehensive legal, technical, operational, and governance controls. Consult qualified legal and compliance professionals for your specific requirements.