Common Artifact Types
VISO TRUST recognizes a wide range of artifact types, including:How Classification Works
When an artifact is uploaded, VISO TRUST’s AI:- Reads and analyzes the document content
- Identifies the artifact type based on structure, language, and document characteristics
- Maps the artifact to the relevant control domains it can validate
- Flags the artifact’s assurance level (high-assurance artifacts like SOC 2 carry more weight than self-attested documents)
Artifact Assurance Hierarchy
Not all artifact types carry equal weight. Every artifact type has a numeric assurance value that maps to one of four levels — Advanced, Standard, Moderate, or Limited — shown as a four-dot meter wherever evidence appears. Assurance is the multiplier applied to a control’s weight when VISO TRUST calculates how much risk the evidence removes. Each type’s own level is listed in-platform under Glossary → Artifact Types, and the levels are defined in Control Domains & Artifact Types. Broadly: Higher assurance:- Third-party audited reports (SOC 2, ISO 27001, HITRUST, PCI DSS)
- Third-party penetration tests
- Vendor-completed questionnaires
- Data processing agreements
- Cyber insurance policies
- Self-attested policies
- Public compliance badges (partial credit only)
- Vendor-authored security summaries
Artifact Validity Periods
Artifacts have validity periods — a SOC 2 report, for example, covers a specific audit period and expires after that window. VISO TRUST tracks artifact expiration and flags when artifacts are approaching their validity end date. When an artifact expires:- Its control coverage receives a lower assurance weighting
- Pending Changes are surfaced on the relationship to signal the gap
- If lifecycle management is enabled, VISO TRUST can automatically request updated documentation from the vendor
Artifact Source Types
VISO TRUST tracks where each artifact came from and labels it in the artifact list as Public or Private:
The Source filter in the artifact list uses the same Public/Private options. Sorting the Source column still groups artifacts by who provided them, and source influences how the artifact is presented in the audit trail.