Common Artifact Types
VISO TRUST recognizes a wide range of artifact types, including:How Classification Works
When an artifact is uploaded, VISO TRUST’s AI:- Reads and analyzes the document content
- Identifies the artifact type based on structure, language, and document characteristics
- Maps the artifact to the relevant control domains it can validate
- Flags the artifact’s assurance level (high-assurance artifacts like SOC 2 carry more weight than self-attested documents)
Artifact Assurance Hierarchy
Not all artifact types carry equal weight. Every artifact type has a numeric assurance value that maps to one of four levels — Advanced, Standard, Moderate, or Limited — shown as a four-dot meter wherever evidence appears. Assurance is the multiplier applied to a control’s weight when VISO TRUST calculates how much risk the evidence removes. Each type’s own level is listed in-platform under Glossary → Artifact Types, and the levels are defined in Control Domains & Artifact Types. Broadly: Higher assurance:- Third-party audited reports (SOC 2, ISO 27001, HITRUST, PCI DSS)
- Third-party penetration tests
- Vendor-completed questionnaires
- Data processing agreements
- Cyber insurance policies
- Self-attested policies
- Public compliance badges (partial credit only)
- Vendor-authored security summaries
Artifact Validity Periods
Artifacts have validity periods — a SOC 2 report, for example, covers a specific audit period and expires after that window. VISO TRUST tracks artifact expiration and flags when artifacts are approaching their validity end date. When an artifact expires:- Its control coverage receives a lower assurance weighting
- Pending Changes are surfaced on the relationship to signal the gap
- If lifecycle management is enabled, VISO TRUST can automatically request updated documentation from the vendor
Artifact Source Types
VISO TRUST tracks where each artifact came from:
Source type is displayed in the artifact list and influences how the artifact is presented in the audit trail.