Assurance catalog
Certifications, attestations, authorizations, validations, and mappings by exact scope.
Trust Center
Talvium publishes a claim only when the legal entity, service boundary, region, issuer, control version, dates, evidence, and customer responsibility are known. Targets and mappings remain labeled as targets and mappings.
Evidence matrix
A facility, information system, network connection, and contractor can each require a different decision owner. Talvium's role is to make the evidence chain repeatable, not to collapse those decisions.
| Layer | Decision owner | Talvium evidence |
|---|---|---|
| Mission and sponsorship | Customer, contracting activity, or qualified prime | Use case, sponsor map, and acquisition path |
| Entity and personnel | Cognizant security and vetting authorities | Entity structure, eligibility, and personnel package |
| Facility | Responsible accrediting authority | Reference design, site delta, tests, and findings |
| Information system | Authorizing official | Boundary, controls, assessment, risk decision, and monitoring |
| Network connection | Network owner and mission authority | Interface, identity, keying, routing, and operating procedures |
| Operations and change | Sponsor and oversight authorities | Configuration history, incidents, maintenance, and reapproval triggers |
Capability set
Certifications, attestations, authorizations, validations, and mappings by exact scope.
Data, operational, technical, and legal control by region.
Identity, network, encryption, confidential processing, supply chain, and incident response.
Model inventory, evaluation, safety, human authority, monitoring, and change.
Provider, customer, partner, and authority responsibilities by service.
Availability, incidents, maintenance, material changes, and evidence expiry.
Next decision
The assurance catalog separates target, mapped, self-assessed, independently assessed, certified, and authorized states.