TrigGuard
TRIGGUARD TRUST

TG-01 compliance mapping

Direct mapping of TG-01 protocol features to the AICPA Trust Services Criteria (SOC 2). Use as reference for internal control documentation. This material is not part of the normative protocol specification - see the TG-01 reference specification for the wire contract.

SOC 2 TSC mapping

SOC2 Control Area TG-01 Protocol Feature Implementation Evidence
CC6.1 (Logical Access)Non-bypassable Execution BoundaryEvery system commit requires a valid Ed25519-signed permit, verified against the issuer's published public key.
CC7.2 (System Ops)Deterministic Auth EngineFail-Closed logic ensures no unauthorized Default-Allow states.
CC7.1 (System Monitoring)Signed Authorization ReceiptsImmutably signed JSON records for every PERMIT/DENY/SILENCE decision.
CC8.1 (Change Management)Policy VersioningThe logic_ref in the SAR traces decisions to specific policy commits.
A1.2 (Availability)Local Sidecar DeploymentLine-rate authorization maintains system availability during network lag.

AUDITOR_NOTE: TrigGuard is a primary control point for automated execution. Proposed intent (from any runtime, including agents) is separated from execution authority: only policy-backed PERMIT with a valid receipt authorizes commit, supporting segregation of duties (SoD) in automated environments.

DOC_HASH: sha256:7a3f...e91b · TG-01-SPEC-1.0.4

← Trust center · Protocol specification · Regulatory mapping