Skip to main content
Understanding how VISO TRUST is structured helps you get more out of the platform. Everything in VISO TRUST is built around a small set of core concepts.

Relationships

A relationship is your record of a business connection with a third-party vendor. It’s the central object in VISO TRUST — every assessment, risk score, advisory, and piece of documentation lives under a relationship. When you create a relationship, you define:
  • Who the vendor is (selected from the VISO TRUST directory or created as a new entry)
  • How you use them (data types they access, systems they touch, business purpose)
  • Who owns the relationship internally (the Business Owner)
Relationships persist over time. As you run new assessments, receive advisories, and update vendor context, the relationship record captures the full history.

Assessments

An assessment is how VISO TRUST evaluates a vendor’s security posture. There are three ways an assessment can happen: Assessments move through defined phases — from creation through collection, review, and completion. See Assessments for the full lifecycle.

Risk Scoring

VISO TRUST calculates two risk scores for every vendor: Inherent Risk — the level of risk before accounting for the vendor’s security controls. Driven by two factors:
  • Impact: how sensitive the data the vendor handles is
  • Likelihood: how exposed the relationship is (what systems they touch, what access they have)
Residual Risk — the level of risk after factoring in the vendor’s actual security controls. A vendor with strong, verified controls will have a lower residual risk than their inherent risk suggests. Risk scores are expressed as No Context, Low, Medium, High, or Extreme, backed by numeric values on a consistent scale.
Residual risk is what you should act on. A vendor with high inherent risk but strong controls may be lower priority than a vendor with medium inherent risk and few verified controls.

Control Framework

VISO TRUST maps all vendor evidence to a control framework — a structured set of security requirements. The default framework is grounded in NIST 800-53 and covers:
  • Security
  • Privacy
  • Artificial Intelligence
  • Resilience
  • Product Security
  • Cyber Insurance
  • Service Locations
Controls are populated by evidence from assessments: a SOC 2 report might satisfy a set of security controls; a DPA might satisfy privacy controls. You can customize which control domains apply to your assessments and build custom frameworks if your program requires it.

Artifact Intelligence

Artifact Intelligence is VISO TRUST’s AI document analysis engine. When a security document is uploaded — whether by you or a vendor — Artifact Intelligence:
  1. Reads and classifies the document
  2. Extracts risk-relevant information
  3. Maps findings to controls in your framework
  4. Flags gaps, anomalies, or areas of concern
Work that takes a human analyst hours is completed in under a minute.

Risk Advisories

Risk Advisories are alerts generated when a vendor in your portfolio experiences a security incident, breach, certification change, or other risk-relevant event. VISO TRUST monitors your vendors continuously and surfaces advisories in real time — so you don’t have to track industry news manually.

VISO Chat Agent

VISO Chat Agent is an AI assistant built into the platform. It can answer questions about your vendor portfolio, surface insights from assessments, and help you understand risk data — in natural language, without writing queries or navigating reports.

Trust Profiles

A Trust Profile allows a vendor organization to proactively share their security documentation with VISO TRUST customers. If a vendor has a trust profile, their documents are pre-loaded when you assess them — reducing the need to chase artifacts.
Ready to see these concepts in action? Follow the Quick Start Guide or jump into Relationships to add your first vendor.