Read. Map. Propose. Approve.
The four-stage loop behind TruSecure's operational governance model. It runs continuously — every day, not in the six weeks before an audit — and every pass through the loop ends the same way: with a named person making a decision on the record.
The loop is what NIS2's management-accountability article (Art. 20) and DORA's management-body responsibility (Art. 5) look like when they are operational rather than aspirational: proposals are machine-cheap, but accountability stays human and attributable.
- Connect
Scoped, read-only connectors ingest state from SIEM/SOAR, ITSM, identity, cloud and MLOps tooling across nineteen integration categories. Nothing is re-keyed; the systems of record stay the systems of record.
- Map
AI reads the incoming state and classifies it against the shared control library — the same library every framework cites, so mapping happens once, not once per regulation.
- Propose
AI drafts control mappings, evidence summaries and gap flags as reviewable proposals, each with its source data attached so a reviewer can check the reasoning, not just the conclusion.
- Approve
A named, authenticated person approves, rejects or amends. That decision — not the AI output — is the record of truth, and it is sealed into the audit trail with identity and timestamp.
What a proposal looks like
Every proposal arrives with its provenance attached: which connector fed it, which control it maps to, which citation it satisfies, and what the AI is asking the reviewer to decide.
{
"proposal": "PR-2026-0193",
"type": "control.mapping",
"control": "AC-2 · Accounts",
"cites": "NIS2 Art. 21(2)(i)",
"basis": "identity connector ·
847 sign-in records",
"confidence": "review advised",
"decision": "pending — assigned
to named reviewer"
}Human-Guided AI, Not Blind Automation
AI proposes. A named person decides. TruSecure's AI never autonomously approves a risk acceptance, marks a control compliant, or submits a regulatory report. The boundary is not a policy promise — it is drawn into the product:
- Reads
- Classifies
- Maps
- Summarizes
- Compares
- Drafts
- Proposes
- Approves a risk acceptance
- Marks a control compliant
- Submits a regulatory report
Routes to a named person
What the loop runs on
The Connect stage reads from the tools you already operate — identity, cloud platforms, endpoint management, SIEM/SOAR, ITSM, HR and more — through read-only connectors scoped to the minimum permission each evidence type requires. Premium connectors for the tools TruSecure resells carry the deepest coverage; marketplace and open-source connectors extend the tail.
Ask an AI about TruSecure
TruSecure operates on a four-stage loop: it connects to existing security and IT systems, uses AI to map incoming data against a shared control library, proposes drafts and flags for review, and requires a named human to approve any output that becomes an accountable decision.
