Trust and assurance
Trust Center
Make the exact scope, owner, date, environment, limitation, and evidence behind a claim visible.
Three-layer architecture
Software. Hardware. Physical environment.
Trust crosses the entire stack and must be supported by the evidence appropriate to each boundary.
Trust layer
Software trust
Policy-aware orchestration, secure lifecycle, identity, logging, provenance, audit, change management, and vulnerability evidence.
ExploreTrust layer
Hardware trust
Component inventory, attestation where available, firmware and configuration baselines, provenance, chain of custody, and maintenance.
ExploreTrust layer
Physical trust
Site control, authorized access, secure areas, monitoring, environmental and power controls, continuity rights, people, and procedures.
ExploreValidation register
Use the right verb for the evidence.
| Evidence state | What it means | Publication rule |
|---|---|---|
| Design intent | Architecture or facility is designed to specified requirements. | No authorization implied. |
| Internal validation | Capacitas has tested a defined control or behavior. | Test scope, method, date, and owner required. |
| Third-party assessment | An independent assessor evaluated a defined scope. | Name assessor, scope, date, findings, and limitations. |
| Contractual requirement | A customer or contract requires a defined control or service. | Requirement is not proof of implementation. |
| Government authorization | An authorized body approved a defined system boundary. | Publish only the exact level, scope, date, and status. |
| Certification or clearance | A named certification or clearance exists. | Do not generalize to unlisted sites, services, or people. |
Mission evidence
Four records for every production node.
Node dossier
Site control, physical boundary, access roster, continuity rights, and incident contacts.
ExploreHardware dossier
Inventory, firmware, configuration, provenance, chain of custody, and maintenance.
ExploreSoftware dossier
Control-plane version, policies, identity, logs, changes, and vulnerabilities.
ExploreWorkload-tier matrix
Permitted customers, data, workloads, exceptions, approvers, and retention.
ExploreNext step
Request assurance information
Describe the framework, environment, product, and scope you need to evaluate. Do not send sensitive information.
Request an assessment