Trust
Compliance grounded in the environment as it actually exists.
Trust automates evidence collection, maps compliance posture to 19 frameworks, and generates regulatory audit reports — all from the live GPS data fabric, with a cryptographically verifiable, immutable audit trail underpinning every finding.
Compliance evidence is collected manually, months after the fact, from systems that have changed.
Regulated enterprises face audits built on CMDB data nobody trusts, evidence gathered in the weeks before the audit, and compliance posture that was accurate at the last assessment but has drifted since. The problem is structural: compliance needs a live, auditable, tamper-evident record of the environment — and most organisations don't have one. Trust provides it. The GPS bitemporal fabric is the compliance substrate: every CI state is recorded, every change is immutable, every finding is traceable to its evidence.
Access certified against
what actually happens.
Not what a role declares.
Most IGA tools certify access by asking a manager whether an employee still needs their declared role — a process that generates attestations, not evidence. Trust certifies access against 90 days of kernel-level behavioral traces from Pathfinder. Access rights that are never exercised are surfaced automatically. Every finding carries the behavioral trace as evidence — not an assertion that certification was completed.
eBPF/ETW kernel-level ops-per-day per access right. Access certified against what a service actually does, not what its role says it can do.
Access rights with zero behavioral activity in the trace period are surfaced automatically — no manual review campaign required to find the exposure.
Every flagged access right comes with the behavioral trace attached as evidence. Auditors see data, not attestation forms.
The same behavioral evidence that certifies access also maps to compliance controls across ISO 27001, SOC 2, NIST CSF, PCI-DSS, and 15 more.
Four steps, end to end.
Inherit the bitemporal audit trail
Every CI state change, relationship update, and health event in the GPS fabric is already hash-chained and immutable. Trust inherits this trail as its compliance substrate — no separate evidence collection infrastructure required.
Map CI state to compliance framework controls
Each discovered CI attribute, configuration state, and access record is automatically mapped to the relevant controls across all 19 supported frameworks. Gaps are surfaced as they open — not at the next audit.
Score compliance posture continuously
Compliance posture is scored per framework, per control domain, and per CI — updated automatically as Pathfinder's discovery data changes. The score reflects the environment as it is, not as it was last quarter.
Generate audit reports with CI-level traceability
Regulatory audit reports are generated from the live fabric — every finding is traced to a specific CI, a specific configuration state, and a specific timestamp. Auditors see evidence, not assertions.
Built for the people who own this problem.
CISO
Continuous compliance posture scoring against all relevant frameworks — not a pre-audit scramble for evidence.
Compliance Officer / GRC Lead
Automated evidence collection that maps to frameworks without requiring manual data entry or spreadsheet management.
Risk Manager
A real-time view of which control areas are drifting out of compliance — before the auditor finds them first.
CIO
Confidence that the organisation's compliance posture is grounded in the actual CI estate, not a static snapshot.
Built different.
Four capabilities you won't find assembled anywhere else.
Continuous posture scoring
Not a point-in-time assessment.
Compliance posture is scored against the live GPS fabric — updated every time Pathfinder updates the CI inventory. When a configuration drifts out of compliance, the finding surfaces immediately. When it's remediated, the posture score updates. No audit cycle required.
19 frameworks from one fabric
Map once. Report to any auditor.
ISO 27001, SOC 2, NIST CSF, CIS Controls, PCI-DSS, HIPAA, and 13 more — all mapped to the same discovered CI data. When a CI attribute satisfies a control in one framework, that evidence is available for all applicable frameworks automatically.
Cryptographically verifiable evidence
Auditors see proof, not promises.
Every compliance finding is backed by evidence from the hash-chained GPS audit trail. The evidence is tamper-evident: any modification to historical CI state breaks the chain. Auditors can verify the integrity of evidence independently — without relying on the organisation's assurance.
CI-level traceability in every report
No assertions without evidence.
Every line in every audit report links to the specific CI, configuration attribute, and timestamp that generated the finding. Auditors can drill from the summary to the raw evidence in a single click. No narrative-only compliance reports.
How Trust stacks up.
14 capabilities across behavioral IGA, compliance posture, and audit evidence quality.
All third-party product names and logos are trademarks of their respective owners and are used for identification and comparison purposes only. Comparisons are based on publicly available product documentation as of 2025–26 and reflect Avennorth's good-faith assessment; they do not imply affiliation, sponsorship, or endorsement.
Indicators and intelligence,
grounded in this product.
Trust feeds behavioral discovery signals into Intelligence, which classifies compliance gap risk by comparing observed access patterns against policy. Competing compliance hypotheses — policy drift, intentional exception, configuration error — are falsified before a finding is written to the audit chain.
- —Compliance gap score
- —Policy drift index
- —Access anomaly rate
- —Audit readiness score
- —Control coverage %
- —Exception rate
- —Remediation velocity
- —Risk acceptance rate
- —Evidence completeness
- —Chain integrity score
- —Regulatory alignment
- —Open finding age
Where Trust fits in the platform.
Trust is only as strong as the discovery data underneath it. A fully deployed Pathfinder layer means compliance evidence is drawn from a continuously refreshed, behaviorally discovered CI estate — not a stale CMDB export.
Receives from
Explore the platform
Get started
See Trust in action.
Thirty minutes. A live environment. Real findings from your own data.
Book a Demo