Common Artifact Types
VISO TRUST recognizes a wide range of artifact types, including:How Classification Works
When an artifact is uploaded, VISO TRUST’s AI:- Reads and analyzes the document content
- Identifies the artifact type based on structure, language, and document characteristics
- Maps the artifact to the relevant control domains it can validate
- Flags the artifact’s assurance level (high-assurance artifacts like SOC 2 carry more weight than self-attested documents)
Artifact Assurance Hierarchy
Not all artifact types carry equal weight. VISO TRUST uses an assurance hierarchy to determine how much confidence to assign to each artifact’s control coverage: Higher assurance:- Third-party audited reports (SOC 2, ISO 27001, HITRUST, PCI DSS)
- Third-party penetration tests
- Vendor-completed questionnaires
- Data processing agreements
- Cyber insurance policies
- Self-attested policies
- Public compliance badges (partial credit only)
- Vendor-authored security summaries
Artifact Validity Periods
Artifacts have validity periods — a SOC 2 report, for example, covers a specific audit period and expires after that window. VISO TRUST tracks artifact expiration and flags when artifacts are approaching their validity end date. When an artifact expires:- Its control coverage receives a lower assurance weighting
- Pending Changes are surfaced on the relationship to signal the gap
- If lifecycle management is enabled, VISO TRUST can automatically request updated documentation from the vendor
Artifact Source Types
VISO TRUST tracks where each artifact came from:
Source type is displayed in the artifact list and influences how the artifact is presented in the audit trail.