Trust / coverage model
One library. No duplicate trail.
Trailbrace is built around a canonical control library, refreshed from the systems that hold the truth. That lets one observation do more work across your program.
The source trust view is intentionally honest about readiness: live workspace counts appear only after controls are seeded. This page describes the coverage model without inventing a number.
Live coverage model
The control library, on display.
Three frameworks, one normalized trail, and a clear owner for each observation.
01 / SOC 2
Trust Services Criteria
AICPA 2017 TSC with the 2022 points of focus.
Ready for shared evidence
02 / ISO 27001
Annex A controls
ISO/IEC 27001:2022 mapped to the same control library.
No second audit project
03 / HIPAA
Security Rule
Technical and administrative safeguards connected to the trail.
One run of controls
Crosswalk / examples
Evidence that travels.
A control library becomes useful when the same clean observation answers more than one question. Here is the shape of that handoff.
| Control family | SOC 2 | ISO 27001 | HIPAA |
|---|---|---|---|
| Logical access · least privilege | CC6.1 | A.5.15 | §164.312(a) |
| External boundary protection | CC6.6 | A.8.20 | §164.312(e) |
| Anomaly detection on production systems | CC7.2 | A.8.16 | §164.308(a)(5) |
| Change management on production code | CC8.1 | A.8.32 | §164.308(a)(8) |
Need the trail in your workspace?