Skip to main content
Trust & Evidence Center

Trust & Evidence Center

Transparent compliance mapping showing how Vallum capabilities relate to enterprise security frameworks. Each mapping includes the support status, evidence Vallum can produce, limitations, customer responsibilities, and external controls required.

Positioning: Vallum is independent proof-grade trust infrastructure for scoped authorization, evidence verification, cryptographic provenance, certification, public verification, and defensible evidence delivery. Vallum integrates with existing systems. It does not require Wayne OS and does not replace identity management, endpoint protection, network security, cloud security, governance, or legal review.

Important: Vallum may produce evidence relevant to the control objectives listed below. Additional organizational, technical, legal, and operational controls may be required. Vallum does not satisfy, guarantee compliance with, make customers compliant with, or claim regulator approval for any framework listed. Compliance is an organizational responsibility that requires comprehensive controls beyond any single product.

Our Trust Principles

Transparency by Default

Every claim on this page includes the support status, limitations, and customer responsibilities. We do not obscure what Vallum does not do.

No Security Theater

We distinguish between evidence Vallum can produce and compliance guarantees (which require comprehensive organizational controls beyond any single product).

Auditor-Friendly Design

Evidence packages are designed to be shared with auditors directly. They are self-contained and independently verifiable without requiring access to Vallum systems.

Honest Boundaries

Vallum is technical infrastructure. It is not legal advice, it is not a compliance certification, and it does not replace human judgment, organizational policies, or comprehensive security programs.

Compliance Mapping

Supported EvidencePartial Technical SupportIntegration RequiredExternal ControlNot AddressedResearch
SOC2CC6.1Logical and Physical Access ControlsSupported Evidence
Version: 2017 Trust Services CriteriaLast reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Titan Handshake produces authorization receipts for every protected operation. Receipts document the identity, tenant, operation type, policies evaluated, and authorization decision. These receipts can be assembled into evidence packages for auditor review.

Limitations

Vallum only produces evidence for operations routed through Titan Handshake. Access controls for systems outside Vallum (network, physical, endpoint) are not covered. Vallum does not enforce physical access controls.

Customer Responsibilities

Integrate all auditable operations with Titan Handshake. Maintain physical and network access controls independently. Ensure identity provider integration is correctly configured.

External Controls Required

Identity provider (IdP), network access controls, physical security, endpoint protection

SOC2CC7.2System Monitoring and Anomaly DetectionPartial Technical Support
Version: 2017 Trust Services CriteriaLast reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Titan Handshake receipts create an immutable record of authorization decisions. Titan Verify assembles these into evidence packages. Denial receipts document blocked operations. These records support monitoring and anomaly detection workflows.

Limitations

Vallum does not perform anomaly detection itself. It produces evidence that can feed into monitoring systems, but does not replace SIEM, alerting, or incident response tooling. Real-time alerting is outside Vallum's scope.

Customer Responsibilities

Implement SIEM or log aggregation. Configure alerting rules. Establish incident response procedures. Route Vallum receipts to monitoring infrastructure.

External Controls Required

SIEM platform, alerting system, incident response procedures, log aggregation

SOC2CC8.1Change ManagementPartial Technical Support
Version: 2017 Trust Services CriteriaLast reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Operations that modify system configuration can be gated through Titan Handshake, producing authorization receipts that document who approved the change, when, and under what policy. Evidence packages can document the change lifecycle.

Limitations

Vallum does not enforce change management processes. It can receipt authorization decisions for changes routed through it, but does not manage change request workflows, approval chains, or rollback procedures.

Customer Responsibilities

Implement change management workflows. Route change approvals through Titan Handshake. Maintain change advisory board processes. Document rollback procedures.

External Controls Required

Change management system, approval workflows, version control, deployment pipelines

ISO 27001A.8.3Information Access RestrictionSupported Evidence
Version: ISO/IEC 27001:2022Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Titan Handshake enforces tenant-scoped authorization for protected operations. Wrong-tenant access fails closed. Private evidence within Verified Ops is tenant-isolated. Authorization receipts document every access decision.

Limitations

Vallum enforces access restriction only for operations routed through Titan Handshake and data within Verified Ops. Application databases, file systems, and third-party services require their own access controls. Vallum does not replace database-level or filesystem-level access restrictions.

Customer Responsibilities

Implement access controls for all data stores. Route sensitive operations through Titan Handshake. Maintain role-based access policies. Conduct regular access reviews.

External Controls Required

Database access controls, filesystem permissions, application-level authorization, role management system

ISO 27001A.12.4.1Event LoggingSupported Evidence
Version: ISO/IEC 27001:2022Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Titan Handshake generates immutable receipts for every protected operation. Titan Verify assembles receipts into evidence packages with manifests. Titan Sign provides cryptographic sealing. These records form a tamper-evident event log for Vallum-protected operations.

Limitations

Vallum only logs events for operations routed through its infrastructure. Application events, system events, network events, and user activity outside Vallum are not captured. Vallum does not replace centralized logging or SIEM.

Customer Responsibilities

Implement centralized logging for all systems. Route auditable operations through Titan Handshake. Maintain log retention policies. Protect log integrity.

External Controls Required

Centralized logging platform, SIEM, log retention policies, log integrity protection

GDPRArticle 25Data Protection by Design and DefaultPartial Technical Support
Version: Regulation (EU) 2016/679Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Tenant-scoped evidence boundaries limit data exposure. Public verification endpoints expose only minimal safe status. Private evidence is tenant-isolated. Authorization receipts document data access decisions.

Limitations

Vallum does not implement data minimization for your application data. It does not control what data your application collects, processes, or retains. Data protection by design must be implemented across your entire data lifecycle, not just within Vallum-protected operations.

Customer Responsibilities

Implement data minimization in application design. Conduct Data Protection Impact Assessments. Maintain privacy-by-design documentation. Implement data retention policies.

External Controls Required

Privacy engineering practices, DPIA process, data classification, retention management, consent management

GDPRArticle 32Security of ProcessingPartial Technical Support
Version: Regulation (EU) 2016/679Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Tenant isolation within Verified Ops, immutable audit trails for protected operations, and cryptographic sealing of evidence packages contribute to security of processing for Vallum-managed operations.

Limitations

Vallum provides security measures for its own infrastructure only. Security of processing across your entire data estate requires comprehensive controls beyond Vallum. Vallum does not encrypt data at rest in your databases, protect your network perimeter, or manage your endpoint security.

Customer Responsibilities

Implement encryption at rest and in transit. Maintain network security. Conduct regular security assessments. Implement incident response procedures.

External Controls Required

Encryption (at rest and in transit), network security, vulnerability management, incident response, security monitoring

EU AI ActArticle 14Human OversightIntegration Required
Version: Regulation (EU) 2024/1689Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Titan Handshake can gate operations that require human approval, producing receipts that document whether human oversight was obtained. Evidence packages can demonstrate that human review occurred before critical operations.

Limitations

Vallum does not implement human oversight interfaces. It can receipt that a human approved an operation (if your workflow routes approvals through Titan Handshake), but it does not provide the UI, notification system, or escalation workflow for human review. Human oversight design is an application-layer responsibility.

Customer Responsibilities

Design human oversight workflows. Implement approval interfaces. Define which operations require human review. Route approval decisions through Titan Handshake for evidence.

External Controls Required

Human review interfaces, escalation workflows, notification systems, role-based approval chains, override mechanisms

EU AI ActArticle 15Accuracy, Robustness, and CybersecurityPartial Technical Support
Version: Regulation (EU) 2024/1689Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Titan Handshake can receipt authorization decisions that gate AI operations, creating evidence of what was permitted. Fail-closed behavior means unauthorized operations are denied. Evidence packages document the operational boundary.

Limitations

Vallum does not make AI models more accurate or robust. It does not validate model outputs, test model performance, or prevent model degradation. Accuracy and robustness are model-layer and application-layer concerns. Vallum provides authorization and evidence infrastructure, not model quality assurance.

Customer Responsibilities

Implement model testing and validation. Monitor model performance. Maintain cybersecurity controls. Conduct adversarial testing. Document accuracy metrics.

External Controls Required

Model testing frameworks, performance monitoring, adversarial testing, cybersecurity controls, accuracy benchmarking

HIPAA§164.312(b)Audit ControlsSupported Evidence
Version: 45 CFR Part 164Last reviewed: 2026-06-15Official source →

Evidence Vallum Can Provide

Immutable authorization receipts for protected operations, evidence packages with complete receipt chains, cryptographically sealed audit records via Titan Sign. These records can support audit control requirements for operations routed through Vallum.

Limitations

Vallum only produces audit records for operations routed through Titan Handshake. PHI access through systems outside Vallum is not captured. Vallum does not replace EHR audit logging, database access logging, or application-level audit trails. Complete HIPAA audit coverage requires controls across all systems touching PHI.

Customer Responsibilities

Implement audit logging across all PHI-touching systems. Route sensitive operations through Titan Handshake. Maintain audit log retention per HIPAA requirements. Conduct regular audit log reviews.

External Controls Required

EHR audit logging, database audit trails, application logging, log retention system, regular audit reviews

Request an Auditor Pack

We can prepare a detailed document covering our architectural security evidence, control mappings, and evidence generation capabilities for your specific audit requirements. This is prepared on request — not a pre-built download.

Request an Auditor Pack

Legal Boundary Notice

This page provides technical information about Vallum capabilities and how they may relate to compliance framework requirements. It is not legal advice. It is not a compliance certification. It does not guarantee that using Vallum will make your organization compliant with any framework. Compliance is an organizational responsibility that requires comprehensive legal, technical, operational, and governance controls. Consult qualified legal and compliance professionals for your specific requirements.