How the platform works
Documented against the implementation rather than the marketing. The catalogue, the signals and the mapping to published requirements given here are the ones in the code, so anything the platform reports can be recomputed by hand.
- 01Getting startedCreate a project, describe your app in eight facts, point the probe at your URL, and see which published requirements it already meets.Read
- 02How coverage is derivedThe mapping from controls to published requirements, what met means, the four tiers, and what the evaluation found.Read
Every page
11 in total- The workThe control catalogueThe 77 controls in 13 categories, the published requirements they satisfy, and how applicability and provider ownership work.
- The workThe four signalsHow each control gets tested: the live URL probe, repository host, your own coding tool, and cross-checks.
- The workFindings and host alertsWhat a failed control produces, how alerts from your repository host appear with their own severity and window, and how findings are closed.
- The workThe published requirementsThe four frameworks every control maps to, how coverage per framework is derived, what is excluded and why, and what is deliberately not covered.
- The workThe threat modelAssets, threats and mitigations, generated from your profile, with each mitigation naming a control in the catalogue.
- The workThe incident runbookThe first sixty minutes, why the runbook is a control, and how an incident in progress appears.
- The workPoliciesGenerating the documents, why publishing one earns nothing by itself, and their standing.
- Sharing itThe public Trust CenterWhat it shows, what it deliberately never shows, the share link for a specific buyer, and where it lives.
- AccountPlans and billingWhat each plan includes, and how billing works.