Skip to main content
Artifact types are the categories VISO TRUST uses to classify security and compliance documents. When an artifact is uploaded — whether by you, a vendor, or discovered publicly — VISO TRUST automatically classifies it into an artifact type and uses that classification to determine which controls it can validate.

Common Artifact Types

VISO TRUST recognizes a wide range of artifact types, including:

How Classification Works

When an artifact is uploaded, VISO TRUST’s AI:
  1. Reads and analyzes the document content
  2. Identifies the artifact type based on structure, language, and document characteristics
  3. Maps the artifact to the relevant control domains it can validate
  4. Flags the artifact’s assurance level (high-assurance artifacts like SOC 2 carry more weight than self-attested documents)
For most artifacts, classification is fully automatic. High-assurance artifacts — SOC 2 reports, ISO certificates, third-party penetration tests — are routed through an additional auditor review step when the AI Assessment + Auditor Review method is configured.

Artifact Assurance Hierarchy

Not all artifact types carry equal weight. VISO TRUST uses an assurance hierarchy to determine how much confidence to assign to each artifact’s control coverage: Higher assurance:
  • Third-party audited reports (SOC 2, ISO 27001, HITRUST, PCI DSS)
  • Third-party penetration tests
Moderate assurance:
  • Vendor-completed questionnaires
  • Data processing agreements
  • Cyber insurance policies
Lower assurance:
  • Self-attested policies
  • Public compliance badges (partial credit only)
  • Vendor-authored security summaries
When a higher-assurance artifact is available, it supersedes older or lower-assurance artifacts of the same type in the risk calculation.

Artifact Validity Periods

Artifacts have validity periods — a SOC 2 report, for example, covers a specific audit period and expires after that window. VISO TRUST tracks artifact expiration and flags when artifacts are approaching their validity end date. When an artifact expires:
  • Its control coverage receives a lower assurance weighting
  • Pending Changes are surfaced on the relationship to signal the gap
  • If lifecycle management is enabled, VISO TRUST can automatically request updated documentation from the vendor

Artifact Source Types

VISO TRUST tracks where each artifact came from: Source type is displayed in the artifact list and influences how the artifact is presented in the audit trail.

Configuring Artifact Type Preferences

Org Admins can configure which artifact types to request by default in collection requests under Settings → Assessments (the Required artifacts section). Whether publicly claimed compliance certifications count toward residual risk is a separate setting, managed under Settings → Risk Model.