TRUST · COMPLIANCE
TG-01 compliance mapping
Direct mapping of TG-01 protocol features to the AICPA Trust Services Criteria (SOC 2). Use as reference for internal control documentation. This material is not part of the normative protocol specification - see the TG-01 reference specification for the wire contract.
SOC 2 TSC mapping
| SOC2 Control Area | TG-01 Protocol Feature | Implementation Evidence |
|---|---|---|
| CC6.1 (Logical Access) | Non-bypassable Execution Boundary | Every system commit requires a valid Ed25519-signed permit, verified against the issuer's published public key. |
| CC7.2 (System Ops) | Deterministic Auth Engine | Fail-Closed logic ensures no unauthorized Default-Allow states. |
| CC7.1 (System Monitoring) | Signed Authorization Receipts | Immutably signed JSON records for every PERMIT/DENY/SILENCE decision. |
| CC8.1 (Change Management) | Policy Versioning | The logic_ref in the SAR traces decisions to specific policy commits. |
| A1.2 (Availability) | Local Sidecar Deployment | Line-rate authorization maintains system availability during network lag. |
AUDITOR_NOTE: TrigGuard is a primary control point for automated execution. Proposed intent (from any runtime, including agents) is separated from execution authority: only policy-backed PERMIT with a valid receipt authorizes commit, supporting segregation of duties (SoD) in automated environments.
DOC_HASH: sha256:7a3f...e91b · TG-01-SPEC-1.0.4
← Trust center · Protocol specification · Regulatory mapping