Skip to main content
TruSecure — Home
PLATFORM

Read. Map. Propose. Approve.

The four-stage loop behind TruSecure's operational governance model. It runs continuously — every day, not in the six weeks before an audit — and every pass through the loop ends the same way: with a named person making a decision on the record.

The loop is what NIS2's management-accountability article (Art. 20) and DORA's management-body responsibility (Art. 5) look like when they are operational rather than aspirational: proposals are machine-cheap, but accountability stays human and attributable.

  1. Connect

    Scoped, read-only connectors ingest state from SIEM/SOAR, ITSM, identity, cloud and MLOps tooling across nineteen integration categories. Nothing is re-keyed; the systems of record stay the systems of record.

  2. Map

    AI reads the incoming state and classifies it against the shared control library — the same library every framework cites, so mapping happens once, not once per regulation.

  3. Propose

    AI drafts control mappings, evidence summaries and gap flags as reviewable proposals, each with its source data attached so a reviewer can check the reasoning, not just the conclusion.

  4. Approve

    A named, authenticated person approves, rejects or amends. That decision — not the AI output — is the record of truth, and it is sealed into the audit trail with identity and timestamp.

What a proposal looks like

Every proposal arrives with its provenance attached: which connector fed it, which control it maps to, which citation it satisfies, and what the AI is asking the reviewer to decide.

proposal.jsonJSONSample data
{
  "proposal": "PR-2026-0193",
  "type": "control.mapping",
  "control": "AC-2 · Accounts",
  "cites": "NIS2 Art. 21(2)(i)",
  "basis": "identity connector ·
    847 sign-in records",
  "confidence": "review advised",
  "decision": "pending — assigned
    to named reviewer"
}

Human-Guided AI, Not Blind Automation

AI proposes. A named person decides. TruSecure's AI never autonomously approves a risk acceptance, marks a control compliant, or submits a regulatory report. The boundary is not a policy promise — it is drawn into the product:

AI does
  • Reads
  • Classifies
  • Maps
  • Summarizes
  • Compares
  • Drafts
  • Proposes
AI never
  • Approves a risk acceptance
  • Marks a control compliant
  • Submits a regulatory report

Routes to a named person

What the loop runs on

The Connect stage reads from the tools you already operate — identity, cloud platforms, endpoint management, SIEM/SOAR, ITSM, HR and more — through read-only connectors scoped to the minimum permission each evidence type requires. Premium connectors for the tools TruSecure resells carry the deepest coverage; marketplace and open-source connectors extend the tail.

See all integrations

Ask an AI about TruSecure

TruSecure operates on a four-stage loop: it connects to existing security and IT systems, uses AI to map incoming data against a shared control library, proposes drafts and flags for review, and requires a named human to approve any output that becomes an accountable decision.