whats-best.ai

Information Security

TrustCloud

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by TrustCloud S.L. · trustcloud.ai

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

TrustCloud, an AI-native continuous control monitoring platform, scores strongest on integrations and automation at 7–8: 150+ integrations across cloud, hybrid and on-premises, an API and SDK reaching on-premises sources, Jira evidence pulled automatically instead of screenshots, and remediation synced into ServiceNow and Jira under human approval. Framework coverage follows at 6–8 and is the widest spread — the lead auditor's 8 credits 18+ out-of-the-box standards on a common control framework, while the skeptic's 6 notes the captured pages give different figures for whether mappings to NIST 800-53, CMMC, PCI DSS, GDPR, CCPA and HITRUST are live or coming soon. Controls and statement of applicability spread 5–7, and audit readiness at 6–7 leans on continuous evidence without public answers on revision-safe change history or point-in-time reconstruction. Sovereignty sits at 1: copyright lines name TrustCloud Corporation while the vendor line names TrustCloud S.L., and we found no public information on hosting location, data residency, a data processing agreement or a subprocessor list. We found no public price figures, and pricing scores are not counted.

Report an error

Speaks for it

  • 150+ integrations across cloud, hybrid and on-premises, with an API and SDK that continuously test on-premises data feeds
  • Jira tickets pulled automatically as audit-ready evidence versions instead of screenshots
  • 18+ out-of-the-box standards plus unlimited custom frameworks, with one satisfied control auto-mapped toward SOC 2, ISO 27001 and HIPAA
  • Deterministic control tests with human-in-the-loop approval on every action and remediation tasks synced into ServiceNow and Jira
  • Residual risk reported in dollars with audience-specific board reporting drawn from one data set

Report an error

Held against it

  • Sovereignty scores sit at 1, with no public information on hosting location, data residency, a data processing agreement or a subprocessor list
  • The captured pages give different figures for the legal entity — copyright lines name TrustCloud Corporation while the vendor line names TrustCloud S.L.
  • We found no public information on statement-of-applicability generation or internal audit workflows with findings management
  • We found no public information on revision-safe change history, point-in-time state reconstruction or auditor access roles
  • We found no public information on a documented risk methodology or incident workflows with statutory reporting clocks

Report an error

Best for

  • You run SOC 2, ISO 27001 and HIPAA programs together and want one satisfied control to advance all of them
  • Your team spends its assessment time gathering evidence by hand and wants it pulled automatically from Jira, Snyk and KnowBe4
  • You already run ServiceNow and Jira and want remediation tasks to land there under human approval
  • You monitor a hybrid or on-premises estate and need an API and SDK that reach it

Report an error

Avoid if

  • You must verify hosting location, data residency, subprocessors or a data processing agreement before signing — sovereignty scores sit at 1 and the captured pages give different figures for the legal entity
  • Your compliance calendar runs on NIS2, DORA, TISAX or BSI IT-Grundschutz — ask the vendor: the public pages we read do not show it
  • You need in-product statement-of-applicability generation and internal audit findings management for a certification project — the controls and statement of applicability scores spread 5–7 partly on this gap
  • You must show an auditor the exact control state on a past date — audit readiness tops out at 6–7 with no public information on revision-safe history or point-in-time reconstruction

Report an error

The scores

Asset & risk management depth

Show reasoning
How this is scored

The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.

0 — No ISMS substance; "information security" is a chapter in the marketing site.

3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.

5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.

8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.

10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.

Report an error

The CISO

TrustRegister is more than a spreadsheet: quantified likelihood and impact, treatment status, residual risk, assigned ownership, forecasting, and a Control Graph that links risks to controls and applications. But we found no public information on a documented risk methodology, protection-needs inheritance across asset relations, or incident workflows with statutory reporting clocks — the breach material is a downloadable assessment template, not a clock-driven process, and that is the part my NIS2 exposure lives or dies on. 3 4 2

Report an error

The GRC Consultant

TrustRegister is a real risk backbone on paper — treatment status, residual risk, ownership with task tracking, quantified board reporting, plus third-party risk assessments — and the control graph carries an application inventory of crown-jewel systems. But we found no public information on a documented risk methodology, protection-needs inheritance across asset relations, or in-product incident workflows with statutory reporting clocks; the breach notification material is a free downloadable template, not capability. 3 1 4 2

Report an error

The Drafted IT Officer

TrustRegister is a real risk backbone in the making: risk scoring, treatment status, residual risk, forecasting and ownership, with the risk register and application inventory wired into a Control Graph that links risks to controls. But I found no public information on a documented risk methodology, inherited protection needs across asset relations, or incident workflows with statutory clocks — the only incident-related item is a downloadable breach notification template, which is not incident handling. 1 3 4

Report an error

The Lead Auditor

The risk register is live rather than a spreadsheet: treatment status, residual risk, assigned ownership, quantified exposure in dollars and board-ready reports are all evidenced, with controls feeding risk measurement. But we found no public information on a documented risk methodology, protection needs inherited across asset relations, or incident workflows with statutory reporting clocks — only a downloadable breach-notification template, which is content, not an incident process. 3 4 1 2

Report an error

The Evidence Integrator

TrustRegister scores risks against live control effectiveness with treatment status, residual risk, ownership and board-ready dollar reporting, and the Control Graph carries an application inventory alongside risks and controls — real risk-backbone material. But I found no public information on a documented risk methodology, inherited protection needs across asset relations, or incident workflows with statutory reporting clocks; the only incident artifact on the captured pages is a downloadable breach-notification template. 1 2 3 4

Report an error

The Skeptic

TrustRegister is described with real-time risk monitoring based on control effectiveness, collaborative ownership and task tracking, quantified likelihood, impact and exposure, and board-ready reporting, and the Control Graph lists application inventory and risk register among its artifacts. We found no public information on a documented risk methodology, inherited protection needs across asset relations, or product-level incident workflows — breach notification appears only as an educational article with a downloadable template. 3 4 2

Report an error

Controls, SoA & measures

Show reasoning
How this is scored

Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.

0 — A static control checklist; applicability, implementation status and evidence are the consultant's spreadsheet.

3 — Control catalogs with status fields, but no SoA generation, no measure ownership, no link between controls and risks.

5 — Controls linked to risks and measures with owners and due dates; SoA producible with manual assembly; internal audit supported by checklists.

8 — SoA on demand from live control status, measure tracking with delegation and escalation, internal audit workflows with findings management, controls carrying their own evidence.

10 — The control fabric as a living system: catalog updates versioned, SoA always current, audit programs with recurring schedules, and every control answerable with linked evidence at any moment.

Report an error

The CISO

Controls sit in a semantic graph mapped to policies, applications, risks and contractual commitments on a common control framework, continuously tested with remediation tasks synced into ServiceNow and Jira — this is a control fabric, not a checklist. We found no public information on statement-of-applicability generation from live status, internal audit workflows with findings management, or measure delegation and escalation, which is exactly what I need around my certificate. 4 5 7

Report an error

The GRC Consultant

The Common Control Framework with bring-your-own-controls, a control graph linking every control to policies, risks and applications, continuous testing, and remediation tasks synced into Jira and ServiceNow is exactly the reusable control fabric I want for client twelve. What holds it back is where certification projects live or die: we found no public information on statement-of-applicability generation or internal audit workflows with findings management. 4 5 7 6

Report an error

The Drafted IT Officer

Controls are linked to risks, policies and measures through a common control framework, auto-generated mappings count one satisfied control toward SOC 2, ISO 27001 and HIPAA at once, and remediation tasks are pushed into ServiceNow and Jira with human approval on every action. I found no public information on statement of applicability generation or internal audit workflows with findings management, and as the person who has to produce a SoA for the certifier, that silence matters to me. 4 5 7

Report an error

The Lead Auditor

Controls are genuinely wired into the environment: the Control Graph links each control to policies, applications and risks, automated tests run continuously, and remediation lands as tasks in Jira and ServiceNow. We found no public information on statement-of-applicability generation, internal audit workflows with findings management, or versioned catalog updates — continuous monitoring is not the same as an operable control side. 4 5 7 10

Report an error

The Evidence Integrator

The control side is genuinely alive: controls map to risks, policies and applications in the Control Graph, are tested continuously with deterministic pass/fail outcomes, and carry their own automatically collected evidence with remediation tasks synced into ServiceNow and Jira. I found no public information on statement-of-applicability generation, internal audit workflows with findings management, or delegation and escalation on measures, which is what separates this from the top band. 4 5 6 9

Report an error

The Skeptic

Controls are linked to policies, applications, risks and contractual commitments in the Control Graph, automation claims to cover technical, documentation and process controls, and satisfying one control propagates progress toward SOC 2, ISO 27001 and HIPAA via a common control framework. We found no public information on statement-of-applicability generation, internal audit workflows or findings management; remediation tasks are synced out to ServiceNow and Jira, and we found no public information on an in-product internal audit program. 4 5 7

Report an error

Framework & standard coverage

Show reasoning
How this is scored

Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.

0 — One framework, hard-coded; anything else is "on the roadmap".

3 — Two or three frameworks as separate checklists; the same control is answered once per framework.

5 — The major regimes for its market with partial cross-mapping; newer regimes (NIS2, DORA) present as content packs of varying depth.

8 — Broad current coverage including NIS2/TISAX/DORA where relevant, one-control-many-frameworks mapping, and visible maintenance as regimes evolve.

10 — Framework coverage as a living product: dozens of regimes, genuine multi-compliance mapping on one data basis, per-industry profiles, and documented update cadence when the standard moves.

Report an error

The CISO

18+ out-of-the-box standards plus unlimited custom frameworks, with one control answer auto-mapped to progress across SOC 2, ISO 27001 and HIPAA and visible product-update cadence — genuine multi-compliance on one data basis. The catalog skews American (CMMC, FedRAMP, SOX ITGC, HIPAA), we found no public information on NIS2, DORA, TISAX or BSI IT-Grundschutz, and the captured pages give different figures for whether mappings to NIST 800-53, CMMC, PCI DSS, GDPR, CCPA and HITRUST are live or announced. 6 7 4

Report an error

The GRC Consultant

Eighteen-plus out-of-the-box standards with unlimited custom frameworks, and TrustOps auto-maps one satisfied control into progress across SOC 2, ISO 27001 and HIPAA — answering a control once is real, and a customer case shows 400 controls mapped to NIST 800-53. But the catalog skews US (CMMC, FedRAMP, HIPAA, HITRUST); we found no public information on NIS2, DORA, TISAX or BSI IT-Grundschutz, the regimes my European clients certify against. 6 7 4

Report an error

The Drafted IT Officer

Eighteen-plus out-of-the-box standards with unlimited custom frameworks, genuine one-control-many-frameworks mapping, and a customer case mapping 400 controls to NIST 800-53 — this is living, mapped coverage rather than parallel checklists. The list is US-heavy though, and I found no public information on NIS2, DORA or TISAX, which are the regimes my European reality runs on; the captured pages also give different figures for which mappings exist now versus which are coming soon. 4 6 7

Report an error

The Lead Auditor

Eighteen-plus named regimes from SOC 2 and ISO 27001 through CMMC, FedRAMP, SOX ITGC and ISO 42001, sitting on a Common Control Framework where one satisfied control advances several programs at once, and the catalog visibly expanded between captured pages. We found no public information on NIS2, DORA, TISAX or BSI IT-Grundschutz — the European regimes my certifications actually run on. 6 7 4

Report an error

The Evidence Integrator

Eighteen-plus standards out of the box plus unlimited custom frameworks — SOC 2, ISO 27001, CMMC, FedRAMP, HIPAA, PCI DSS, SOX ITGC, ISO 42001, NIST AI RMF — with a common control framework and auto-generated mappings so one satisfied control feeds many regimes, and product-update pages showing mappings still being extended. I found no public information on NIS2, TISAX, DORA or BSI IT-Grundschutz, nor per-industry profiles, and the captured pages give different figures for which of these standards are currently mapped. 2 4 6 7

Report an error

The Skeptic

Eighteen-plus out-of-the-box standards are listed with auto-generated mappings that carry one satisfied control toward several regimes, and a customer case maps 400 controls to NIST 800-53. The captured pages give different signals on whether mappings for CMMC, PCI-DSS, GDPR, CCPA and HITRUST are live today versus coming soon, and we found no public information on NIS2, DORA, TISAX or BSI IT-Grundschutz coverage. 6 7 4

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators, evidence attachments per control; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous evidence status per framework and scope, exportable proof packs an external auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The CISO

Evidence is collected at the source — a Jira link becomes an audit-ready ticket artifact, Snyk and KnowBe4 runs generate their own control evidence, and every AI output is cited and auditable with no sampling. We found no public information on revision-safe change history, auditor access roles, or a defensible answer to show me the state on a given date, so the standing-audit-file question remains open. 9 11 1

Report an error

The GRC Consultant

Continuous evidence-backed assurance, audit-ready Jira tickets pulled automatically instead of screenshots, outputs that are cited and auditable, and posture sharing with auditors — that is standing audit readiness rather than a pre-audit scramble. The gap is the first question a disputed finding raises: we found no public information on revision-safe change history or reconstructing the control state on a given date. 9 5 7 1

Report an error

The Drafted IT Officer

Evidence collection is this vendor's showpiece: a Jira link is automatically pulled as an audit-ready ticket version instead of screenshots, every output is cited and auditable, and posture can be shared with auditors and the board with a regulator-specific report generated from one data set. I found no public information on revision-safe change history or dedicated auditor access roles, so I have no evidence it can answer "show me the state on date X" — the question my external auditor will actually ask. 1 5 7 9

Report an error

The Lead Auditor

Evidence is collected automatically and cited — a Jira link pulls an audit-ready ticket in place of screenshots, every output is traceable to a graph node, and posture is shareable with auditors and the board from one data set. But we found no public information on revision-safe change history, point-in-time state reconstruction, or auditor access roles, so the question every external auditor asks first — the state on a given date — has no evidenced answer. 9 5 4 1 7

Report an error

The Evidence Integrator

Evidence collection is continuous and machine-fed — Jira tickets pulled as audit-ready versions replacing screenshots, Snyk and KnowBe4 tests feeding controls directly, every output cited with no sampling — and sharing posture with auditors is a named capability. I found no public information on revision-safe change history, auditor access roles, or a defensible reconstruction of the state on a past date, which is the difference between continuous freshness and standing audit proof. 1 5 9 11

Report an error

The Skeptic

Automatic evidence collection is live for Jira, pulling audit-ready ticket versions instead of screenshots, outputs are described as cited and auditable, and posture sharing with auditors plus audience-specific board reports from one data set are marketed. We found no public information on revision-safe change history, date-specific reconstruction, audit-scoped evidence packs or auditor access roles; the zero-hallucination and auditable-AI claims are the vendor's own marketing. 9 5 6 1

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing, CMDB or SSO); automation is reminders and recurrence.

8 — Real connector set (Jira/ServiceNow-class ticketing, CMDB, cloud and endpoint sources), webhooks, SSO/SCIM, automated evidence tests with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, continuous control monitoring against the live estate, and automation that measurably removes the recurring toil rather than renaming it.

Report an error

The CISO

A documented API and SDK, 150+ integrations across cloud, hybrid and on-premises including CMDB records and identity data, native ServiceNow IRM and Jira connectors that feed the existing stack rather than replace it, and deterministic agents running checks with human-in-the-loop approval — continuous monitoring against the live estate, not re-typed evidence. We found no public information on SSO/SCIM or webhooks, which keeps it just short of infrastructure parity. 10 5 4

Report an error

The GRC Consultant

This is a platform that feeds from the real estate: 150-plus integrations across cloud, hybrid and on-premises, an API and SDK that continuously test data feeds and retrieve systems, policies and control health, and agents generating remediation tasks synced into ServiceNow and Jira under human approval. Connectors like Snyk, KnowBe4 and BambooHR automate specific evidence tests, and the vendor reports automated evidence collection freeing over half of team capacity. We found no public information on SSO or SCIM provisioning or webhook event streams. 5 10 9 11 1

Report an error

The Drafted IT Officer

This is the strongest area: 150+ integrations with named connectors for ServiceNow, Splunk, Jira, Snyk and KnowBe4, an API and SDK that reach on-premises and regulated environments, CMDB records and identity data among the sources, and automated evidence tests with human approval before anything acts. It feeds my existing tools instead of replacing them, which I like; I found no public information on webhooks or SSO and SCIM provisioning, which keeps it just short of behaving like infrastructure. 4 5 9 10 11

Report an error

The Lead Auditor

This platform is fed rather than typed into: 150+ integrations across cloud, hybrid and on-premises, ServiceNow and Jira-class ticketing with automatic evidence collection, Splunk, CMDB and identity feeds, and an API plus SDK for continuous testing of on-premises data with human approval on every automated action. We found no public information on webhooks, SSO/SCIM or event streams, which is what separates this from infrastructure grade. 5 10 9 11 4

Report an error

The Evidence Integrator

The estate is live in this product: 150+ connectors across cloud, hybrid and on-premises, CMDB records, identity data, cloud configs and SaaS audit logs as data sources, an API and SDK that continuously test data feeds even in regulated on-premises environments, and remediation flowing back into ServiceNow and Jira with human approval on every action. What keeps it from the top band: I found no public information on webhooks, SSO/SCIM provisioning or event streams, and the API page describes retrieving essential information rather than full parity with the product's own data model. 1 5 9 10 11

Report an error

The Skeptic

ServiceNow, Splunk, Jira, Snyk, KnowBe4 and BambooHR integrations are documented with named control tests and live automatic evidence collection, and the API and SDK reach on-premises sources with CMDB records among the data feeds. The 150-plus integrations headline is supported by only a handful of named connectors on the captured pages, and we found no public information on webhooks, SSO or SCIM directory provisioning. 9 10 11 4 5

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your risk register.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The CISO

The vendor line names TrustCloud S.L. while every copyright names TrustCloud Corporation, with ServiceNow disclosed as a strategic investor, and we found no public information on jurisdiction, ownership, hosting location, data residency, subprocessors or a published DPA. For the system that would hold my risk register — itself a target — an entirely undocumented chain is disqualifying as it stands. 1 3

Report an error

The GRC Consultant

For the system that would hold my clients' entire risk register, we found no public information on legal entity jurisdiction, hosting location, data residency, subprocessors, or a data processing agreement. The captured pages give different signals for the entity — the vendor line reads TrustCloud S.L. while the copyright notices read TrustCloud Corporation — and with no published subprocessor list or DPA I cannot place the risk register under European control. 2 6

Report an error

The Drafted IT Officer

The only entity the pages themselves name is "TrustCloud Corporation" in the copyright line, while the vendor record names TrustCloud S.L. — and I found no public information on hosting location, data residency, a DPA, or any subprocessor list. For the system that would hold my entire risk register, I cannot tell from public pages whose law my security posture lives under, and that is disqualifying for me even before the price question. 4 6 7

Report an error

The Lead Auditor

The captured copyright lines name TrustCloud Corporation as holder of the marks, while the vendor is recorded as a Spanish company, and we found no public information on hosting location, data residency, a DPA, TOMs or a subprocessor list. For the system that would hold my client's risk register — itself a target — that is an undocumented chain from end to end. 3 6 4

Report an error

The Evidence Integrator

The captured pages give different figures for the legal entity — every copyright line names TrustCloud Corporation while the vendor header names TrustCloud S.L. — and beyond GDPR appearing as a framework the product tracks for customers, I found no public information on hosting location, a data processing agreement, or any subprocessor list. For the system that would hold the risk register itself, that is no published posture at all. 1 2 3 6

Report an error

The Skeptic

Every captured page names the vendor as TrustCloud Corporation without stating its jurisdiction, and the framework set on offer leans heavily toward US regimes. We found no public information on hosting locations, data residency, a data processing agreement or a subprocessor list — for the platform that would hold the buyer's risk register. 2 6

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, scale steps or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a certification project is a two-minute exercise.

Report an error

The CISO

A pricing link exists in the navigation, but we found no public price figures on any captured page — no editions, no module prices, no billing period, no setup fees, no consulting split — and the offered path is Schedule a Demo. The real invoice is incomputable from public pages alone. 1 3

Report an error

The GRC Consultant

A pricing link exists in the site navigation, but we found no public information on actual prices, editions, module boundaries or billing terms, and the buying route is a scheduled demo. For a product sold as named modules like TrustOps, TrustRegister and TrustHQ, I cannot compute even a first-year invoice from the public pages. 1 3

Report an error

The Drafted IT Officer

A pricing link exists on the site, but no price figures, editions, user or entity boundaries, or setup fees appear anywhere I could see — the module family (TrustLens, TrustOps, TrustRegister, TrustHQ) is entirely unpriced in public. With a six-month go-live promise and a Fortune 500 target customer, this reads like a sales conversation per configuration, which is normal for this market but leaves me unable to compute anything. 1 7

Report an error

The Lead Auditor

A Pricing entry appears in the navigation and the conversion path shown is scheduling a demo; we found no public information on price figures, billing periods, module boundaries or setup fees. The real invoice is a sales conversation, which is normal for this market but leaves the buyer with nothing to compute. 1 3

Report an error

The Evidence Integrator

A pricing page is listed in the site navigation, but the captured pages show no price figures, edition boundaries, billing periods or setup fees, and the buying path shown is scheduling a demo. On the published evidence alone, the real invoice is a sales conversation. 1 3

Report an error

The Skeptic

A pricing page exists in the site navigation, but the captured content contains no price figures, edition boundaries or per-module numbers, and the stated motion is "Schedule a Demo". We found no public information separating software from services or stating billing periods, so no invoice can be computed from the public pages alone. 1 3

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (11)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page trustcloud.ai Checked 29 Sep 2026 Details →
  2. 2 Asset & risk management depth — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  3. 3 Asset & risk management depth — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  4. 4 Controls, SoA & measures — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  5. 5 Controls, SoA & measures — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  6. 6 Framework & standard coverage — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  7. 7 Framework & standard coverage — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  8. 8 Audit readiness & evidence — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  9. 9 Audit readiness & evidence — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  10. 10 Integrations & automation — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →
  11. 11 Integrations & automation — found from sitemap www.trustcloud.ai Checked 1 Oct 2026 Details →