What
Certification, attestation, authorization, validation, or alignment.
Trust / Assurance
The items below are candidate evidence frameworks. Talvium does not claim certification, attestation, authorization, or validation unless a future catalog record names the exact scope and evidence.
Evidence matrix
| Layer | Candidate framework | Permitted language now |
|---|---|---|
| Information security management | ISO/IEC 27001 | Program target; no certification claim |
| Cloud controls | ISO/IEC 27017; CSA CCM / STAR | Control mapping target; assessment level not claimed |
| Cloud privacy | ISO/IEC 27018; ISO/IEC 27701 | Control target; no independent result claimed |
| AI management | ISO/IEC 42001; NIST AI RMF | Governance program under development |
| Service controls | SOC reporting where commercially required | Future report must name type, period, and system boundary |
| Cryptography | FIPS 140-3 validated modules | Only a named module and certificate may be described as validated |
| National / public sector | Country- and sector-specific obligations | Separate jurisdiction profile and legal review |
| U.S. federal if pursued | FedRAMP, DoD, or agency ATO | Only the exact authorized offering and authoritative registry status |
Capability set
Certification, attestation, authorization, validation, or alignment.
Issuer, auditor, authorizing authority, legal entity, and internal owner.
Service boundary, products, regions, facilities, and operating entities.
Control version, assessment period, issue date, expiry, and next review.
Certificate, report, package, registry identifier, and access conditions.
Provider, partner, customer, and configuration caveats.
Evidence note
For U.S. federal cloud offerings, the FedRAMP Marketplace is the authoritative public source for status. Talvium currently makes no FedRAMP authorization claim.
FedRAMP Marketplace