Trust TRU-005

Platform security

Platform security explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. Trust comes from showing how a conclusion was reached, where the boundary sits and what the evidence cannot establish.

Bounded, non-exploitative Authorised external assessment.

Bounded evidence. Explicit responsibility. No hidden inference.

The useful answer

Platform security explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals.

Platform security explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. Platform security explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. Trust comes from showing how a conclusion was reached, where the boundary sits and what the evidence cannot establish.

Route-specific context

The decision this page is designed to support

01
Review audience
Security reviewer, buyer
02
Control objective
Review product-security controls and assurance evidence. Platform security explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals.
03
Proof boundary
Tenant isolation, delegated access, AAL2 controls and bounded signed downloads protect customer evidence. Evidence basis: RLS, delegation and cross-tenant tests.

A deliberate path

From permission to retained evidence

  1. 01

    Review the governed control described by platform security.

  2. 02

    Trace each statement to its stated evidence basis, owner and review date.

  3. 03

    Carry the published limitation into procurement, assurance or technical interpretation rather than treating silence as approval.

Evidence before assertion

What the product can support

Every governed capability ends with an explicit disposition. Current observations can support a strength or an action; missing, stale or unavailable evidence remains an unknown and cannot become reassurance. Tenant isolation, delegated access, AAL2 controls and bounded signed downloads protect customer evidence.

Qualified statement

Portfolio and MSP workflows separate tenants, domains, responsibility and delegated access.

RLS, delegation and cross-tenant tests

Direct answers

Questions a careful reader should ask

What does Platform security establish?

Platform security explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. It establishes only what the governed evidence supports.

What does it not establish?

It does not prove complete organisational security, exploitability, breach likelihood or the absence of unobserved weaknesses.

How can I verify the conclusion?

Use the linked evidence or capability record to inspect source, observation time, target, responsibility and the condition required for closure.