Vallum Trust Atlas
Evidence Mapping for AI Compliance
Comprehensive documentation of what evidence Vallum produces, what it does not produce, and what remains your responsibility — mapped across 8 compliance frameworks, 150 AI threat models, and 150 reference architectures.
Important: This atlas documents evidence relevance, not compliance certification. Vallum does not certify compliance with any framework. Each mapping shows what evidence Vallum can produce to support your compliance program — full compliance requires complementary controls at infrastructure, organizational, and procedural levels.
Control Evidence by Framework
NIST SP 800-53
44 control evidence mappings
FedRAMP High
25 control evidence mappings
NIST AI RMF
20 control evidence mappings
NIST GenAI Profile
12 control evidence mappings
HIPAA
30 control evidence mappings
EU AI Act
25 control evidence mappings
GDPR
18 control evidence mappings
SOC 2
15 control evidence mappings
ISO 27001
11 control evidence mappings
Control Evidence Mappings
Per-control documentation showing what evidence Vallum produces, what it does not, limitations, and customer responsibilities.
Browse all 200 controls →AI Threat Models
Threat-specific analysis showing how Vallum's containment strategy addresses each vector, with honest limitations.
Browse all 150 threats →Reference Architectures
Deployment patterns showing where Vallum fits in real infrastructure stacks, with integration boundaries clearly marked.
Browse all 150 architectures →Recently Published
AC-1: Establish access control policy and procedures for organizational systems
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-2: Manage system accounts including establishment, activation, modification, review, disabling, and removal
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-3: Enforce approved authorizations for logical access to information and system resources
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-4: Enforce approved authorizations for controlling the flow of information within the system and between systems
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-5: Separate duties of individuals to reduce risk of malevolent activity
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-6: Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-7: Enforce a limit of consecutive invalid logon attempts and take action when maximum is exceeded
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-8: Display system use notification message before granting access
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-11: Prevent further access to the system by initiating a session lock after a defined period of inactivity
NIST SP 800-53 · SUPPORTED EVIDENCE
AC-12: Automatically terminate a user session after defined conditions
NIST SP 800-53 · SUPPORTED EVIDENCE
Legal boundary: The Vallum Trust Atlas is technical reference documentation. It does not constitute legal advice, compliance certification, or audit opinion. Framework control descriptions are sourced from publicly available government and standards-body publications and are summarized under fair use for educational reference. Consult qualified legal and compliance professionals for your specific regulatory obligations.