Avennorth
Avennorth/Trust
07Compliance & Governance

Trust

Compliance grounded in the environment as it actually exists.

Trust automates evidence collection, maps compliance posture to 19 frameworks, and generates regulatory audit reports — all from the live GPS data fabric, with a cryptographically verifiable, immutable audit trail underpinning every finding.

19
Compliance frameworks
ISO 27001, SOC 2, NIST CSF, CIS, PCI-DSS, HIPAA, and 13 more — continuously mapped against live CI data
Auto
Evidence collection
Compliance evidence is drawn from the live CMDB — no manual gathering, no pre-audit scramble
Immutable
Audit snapshots
Every compliance state is cryptographically hash-chained — point-in-time posture is verifiable at any past timestamp
0
Manual compliance spreadsheets
Trust generates regulatory reports from the GPS data fabric — no separate compliance data entry required
The Problem

Compliance evidence is collected manually, months after the fact, from systems that have changed.

Regulated enterprises face audits built on CMDB data nobody trusts, evidence gathered in the weeks before the audit, and compliance posture that was accurate at the last assessment but has drifted since. The problem is structural: compliance needs a live, auditable, tamper-evident record of the environment — and most organisations don't have one. Trust provides it. The GPS bitemporal fabric is the compliance substrate: every CI state is recorded, every change is immutable, every finding is traceable to its evidence.

Behavioral Certification

Access certified against
what actually happens.
Not what a role declares.

Most IGA tools certify access by asking a manager whether an employee still needs their declared role — a process that generates attestations, not evidence. Trust certifies access against 90 days of kernel-level behavioral traces from Pathfinder. Access rights that are never exercised are surfaced automatically. Every finding carries the behavioral trace as evidence — not an assertion that certification was completed.

Behavioral, not declarative

eBPF/ETW kernel-level ops-per-day per access right. Access certified against what a service actually does, not what its role says it can do.

Never-used right detection

Access rights with zero behavioral activity in the trace period are surfaced automatically — no manual review campaign required to find the exposure.

Evidence-attached reclaim queue

Every flagged access right comes with the behavioral trace attached as evidence. Auditors see data, not attestation forms.

19 frameworks from one trace

The same behavioral evidence that certifies access also maps to compliance controls across ISO 27001, SOC 2, NIST CSF, PCI-DSS, and 15 more.

TRUST — BEHAVIORAL ACCESS CERTIFICATIONLIVE
SERVICE
payment-api-prod
DECLARED ROLE
svc-payment-admin
TRACE PERIOD
90d eBPF
ACCESS RIGHTOPS / DAYBEHAVIORAL USAGESTATUS
db.transactions.write
CONFIRMED
db.audit.read
CONFIRMED
s3.receipts.write
CONFIRMED
admin.config
NEVER USED
admin.override
NEVER USED
CERTIFICATION RESULT
3access rights confirmed
2rights flagged for reclaim
90d hash-chained eBPF · tamper-evident
19frameworks mapped
90dbehavioral trace
Autoevidence collection
Zeromanual gathering
How It Works

Four steps, end to end.

01

Inherit the bitemporal audit trail

Every CI state change, relationship update, and health event in the GPS fabric is already hash-chained and immutable. Trust inherits this trail as its compliance substrate — no separate evidence collection infrastructure required.

02

Map CI state to compliance framework controls

Each discovered CI attribute, configuration state, and access record is automatically mapped to the relevant controls across all 19 supported frameworks. Gaps are surfaced as they open — not at the next audit.

03

Score compliance posture continuously

Compliance posture is scored per framework, per control domain, and per CI — updated automatically as Pathfinder's discovery data changes. The score reflects the environment as it is, not as it was last quarter.

04

Generate audit reports with CI-level traceability

Regulatory audit reports are generated from the live fabric — every finding is traced to a specific CI, a specific configuration state, and a specific timestamp. Auditors see evidence, not assertions.

Who It's For

Built for the people who own this problem.

01

CISO

Continuous compliance posture scoring against all relevant frameworks — not a pre-audit scramble for evidence.

02

Compliance Officer / GRC Lead

Automated evidence collection that maps to frameworks without requiring manual data entry or spreadsheet management.

03

Risk Manager

A real-time view of which control areas are drifting out of compliance — before the auditor finds them first.

04

CIO

Confidence that the organisation's compliance posture is grounded in the actual CI estate, not a static snapshot.

Why Trust

Built different.

Four capabilities you won't find assembled anywhere else.

01

Continuous posture scoring

Not a point-in-time assessment.

Compliance posture is scored against the live GPS fabric — updated every time Pathfinder updates the CI inventory. When a configuration drifts out of compliance, the finding surfaces immediately. When it's remediated, the posture score updates. No audit cycle required.

02

19 frameworks from one fabric

Map once. Report to any auditor.

ISO 27001, SOC 2, NIST CSF, CIS Controls, PCI-DSS, HIPAA, and 13 more — all mapped to the same discovered CI data. When a CI attribute satisfies a control in one framework, that evidence is available for all applicable frameworks automatically.

03

Cryptographically verifiable evidence

Auditors see proof, not promises.

Every compliance finding is backed by evidence from the hash-chained GPS audit trail. The evidence is tamper-evident: any modification to historical CI state breaks the chain. Auditors can verify the integrity of evidence independently — without relying on the organisation's assurance.

04

CI-level traceability in every report

No assertions without evidence.

Every line in every audit report links to the specific CI, configuration attribute, and timestamp that generated the finding. Auditors can drill from the summary to the raw evidence in a single click. No narrative-only compliance reports.

Competitive Comparison

How Trust stacks up.

14 capabilities across behavioral IGA, compliance posture, and audit evidence quality.

CAPABILITY
TRUST
by Avennorth
SailPoint Identity
CyberArk Identity
Okta IGA
Access Evidence & Certification
Behavioral access certification (kernel-level)
Access rights certified against kernel-level behavioral evidence — eBPF/ETW traces of actual ops-per-day, not attestation against a declared role that may not reflect what the service actually does
eBPF/ETW behavioral evidence certifies access against actual usage, not declared roles
ROLE ATTESTATION
ROLE-BASED PAM
DECLARED ROLES
Quantified usage per access right
Exact ops-per-day per access right per service measured from kernel-level traces — not last-login signals, not session counts, but the actual behavioral footprint of each permission in use
eBPF ops-per-day per access right: exact quantity, 90d trace, hash-chained
NOT AVAILABLE
PRIVILEGED SESSION
NOT AVAILABLE
Declared role vs behavioral gap detection
Access rights that exist in the declared role but are never exercised in the behavioral trace are surfaced automatically — closing the gap between what an identity is allowed to do and what it actually does
Never-exercised access rights surfaced automatically from 90d behavioral trace
LAST LOGIN SIGNAL
NOT AVAILABLE
USAGE ANALYTICS
Ghost & orphan account detection
Services, accounts, and access rights with zero behavioral activity detected from the eBPF trace — not inferred from account metadata, but confirmed from the absence of kernel-level ops
Zero-ops accounts and access rights flagged from behavioral trace — no activity for N days
ACCOUNT LIFECYCLE
PAM VAULTING
LIFECYCLE MGMT
Automated access reclaim from behavioral evidence
Never-used access rights auto-flagged for reclaim with the behavioral evidence trace attached — not a manual review campaign, not a role-mining exercise, but a behaviorally-evidenced remediation queue
Never-used rights auto-flagged with attached 90d eBPF evidence for reclaim
JOINER-MOVER-LEAVER
NOT AVAILABLE
WORKFLOW AUTOMATION
Compliance & Audit Posture
Continuous compliance posture scoring
Compliance posture scored against 19 frameworks from the live GPS data fabric — updated automatically as Pathfinder discovers CI state changes, not refreshed at the next quarterly assessment
Live posture against 19 frameworks — updated as Pathfinder CI inventory changes
COMPLIANCE MGMT
NOT AVAILABLE
NOT AVAILABLE
19-framework multi-mapping from one fabric
ISO 27001, SOC 2, NIST CSF, CIS Controls, PCI-DSS, HIPAA, and 13 more — all mapped to the same discovered CI data. Evidence that satisfies one control is available for all applicable frameworks
ISO 27001, SOC 2, NIST CSF, CIS, PCI-DSS, HIPAA + 13 more from single data source
FRAMEWORK SUPPORT
PAM FOCUSED
IDENTITY ONLY
Automated evidence collection
Compliance evidence drawn from the live GPS fabric — no pre-audit data gathering sprint, no manual collection of screenshots or exports, no evidence assembled in the weeks before the auditor arrives
Evidence auto-collected from GPS fabric — no manual gathering, no pre-audit sprint
PARTIAL AUTOMATION
MANUAL EXPORTS
LOGS + REPORTS
CI-level evidence traceability in reports
Every line in every audit report links to the specific CI, configuration attribute, and timestamp that generated the finding — auditors drill from summary to raw evidence in one click
Every finding traces to CI + attribute + timestamp in live CMDB — one-click drill-down
USER-LEVEL ONLY
SESSION RECORDING
NOT AVAILABLE
Bitemporal compliance replay
Point-in-time compliance posture verifiable at any past timestamp — any past audit date, any past regulatory snapshot — because every CI state is recorded bitemporally in the GPS fabric
Any past audit date verifiable — bitemporal CI fabric, not a quarterly snapshot
NOT AVAILABLE
NOT AVAILABLE
NOT AVAILABLE
Platform & Integration
GPS Pathfinder behavioral grounding
All compliance evidence sourced from live eBPF-discovered CI data — no dependency on a manually-maintained CMDB, no stale configuration snapshots, no export-and-import synchronisation gap
Compliance substrate is live Pathfinder behavioral discovery — zero manual CMDB entry
CMDB-DEPENDENT
INDEPENDENT
INDEPENDENT
Cryptographic hash-chained audit log
Every CI state change, relationship update, and compliance event is hash-chained and tamper-evident — any modification to historical CI state breaks the chain, providing independently verifiable evidence integrity
Tamper-evident hash chain — any historical modification is detectable by auditors
NOT AVAILABLE
SESSION LOGS
NOT AVAILABLE
Pathfinder-derived CMDB as compliance substrate
Compliance posture maps to the same CI records Pathfinder writes to ServiceNow — not a separate compliance data store that requires synchronisation with the infrastructure estate
Compliance maps to live Pathfinder → ServiceNow CI records — same substrate, no sync
SEPARATE CMDB
SEPARATE CMDB
SEPARATE CMDB
Cross-product intelligence chain
Receives live CI and health data from Pathfinder and Bearing; sends compliance posture and regulatory risk signals to Compass for the CISO and CIO executive personas — no manual export between systems
Pathfinder + Bearing → Trust → Compass: compliance posture in the executive view
STANDALONE
STANDALONE
STANDALONE
COVERAGE (FULL OR PARTIAL)
14 / 14
6 / 14
3 / 14
4 / 14
Full native support
Partial / manual / integration required
Not available

All third-party product names and logos are trademarks of their respective owners and are used for identification and comparison purposes only. Comparisons are based on publicly available product documentation as of 2025–26 and reflect Avennorth's good-faith assessment; they do not imply affiliation, sponsorship, or endorsement.

POWERED BY INTELLIGENCE

Indicators and intelligence,
grounded in this product.

HOW INTELLIGENCE REASONS HERE

Trust feeds behavioral discovery signals into Intelligence, which classifies compliance gap risk by comparing observed access patterns against policy. Competing compliance hypotheses — policy drift, intentional exception, configuration error — are falsified before a finding is written to the audit chain.

COMPLIANCE INDICATORS
  • Compliance gap score
  • Policy drift index
  • Access anomaly rate
  • Audit readiness score
GOVERNANCE INDICATORS
  • Control coverage %
  • Exception rate
  • Remediation velocity
  • Risk acceptance rate
AUDIT INDICATORS
  • Evidence completeness
  • Chain integrity score
  • Regulatory alignment
  • Open finding age
STAKEHOLDER SIGNALS
CISO
Access anomaly rate and compliance gap score
Compliance Officer
Policy drift and exception rate by control
Audit Lead
Evidence completeness and chain integrity
Intelligence Chain

Where Trust fits in the platform.

Trust is only as strong as the discovery data underneath it. A fully deployed Pathfinder layer means compliance evidence is drawn from a continuously refreshed, behaviorally discovered CI estate — not a stale CMDB export.

Get started

See Trust in action.

Thirty minutes. A live environment. Real findings from your own data.

Book a Demo