> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Artifact Type Configuration

> How VISO TRUST artifact types classify security documents like SOC 2 and ISO 27001 reports, and how that classification drives which controls they validate.

**Artifact types** are the categories VISO TRUST uses to classify security and compliance documents. When an artifact is uploaded — whether by you, a vendor, or discovered publicly — VISO TRUST automatically classifies it into an artifact type and uses that classification to determine which controls it can validate.

## Common Artifact Types

VISO TRUST recognizes a wide range of artifact types, including:

| Artifact Type             | Examples                                                    |
| ------------------------- | ----------------------------------------------------------- |
| SOC 2 Type II             | AICPA SOC 2 audit reports                                   |
| ISO 27001                 | Certification and Statement of Applicability                |
| Penetration Test          | Third-party pen test reports                                |
| HITRUST                   | HITRUST CSF certification or validation report              |
| PCI DSS                   | Attestation of Compliance (AOC), Report on Compliance (ROC) |
| Privacy Policy            | Public-facing privacy policy documents                      |
| Data Processing Agreement | DPAs, data handling agreements                              |
| Sub-Processor List        | List of sub-processors or subservicers                      |
| Cyber Insurance Policy    | The vendor's cyber insurance policy                         |
| ISO 42001                 | AI management system certification                          |
| Security Policy           | Internal security policies shared by the vendor             |

## How Classification Works

When an artifact is uploaded, VISO TRUST's AI:

1. Reads and analyzes the document content
2. Identifies the artifact type based on structure, language, and document characteristics
3. Maps the artifact to the relevant control domains it can validate
4. Flags the artifact's assurance level (high-assurance artifacts like SOC 2 carry more weight than self-attested documents)

For most artifacts, classification is fully automatic. High-assurance artifacts — SOC 2 reports, ISO certificates, third-party penetration tests — are routed through an additional auditor review step when the **AI Assessment + Auditor Review** method is configured.

## Artifact Assurance Hierarchy

Not all artifact types carry equal weight. VISO TRUST uses an assurance hierarchy to determine how much confidence to assign to each artifact's control coverage:

**Higher assurance:**

* Third-party audited reports (SOC 2, ISO 27001, HITRUST, PCI DSS)
* Third-party penetration tests

**Moderate assurance:**

* Vendor-completed questionnaires
* Data processing agreements
* Cyber insurance policies

**Lower assurance:**

* Self-attested policies
* Public compliance badges (partial credit only)
* Vendor-authored security summaries

When a higher-assurance artifact is available, it supersedes older or lower-assurance artifacts of the same type in the risk calculation.

## Artifact Validity Periods

Artifacts have validity periods — a SOC 2 report, for example, covers a specific audit period and expires after that window. VISO TRUST tracks artifact expiration and flags when artifacts are approaching their validity end date.

When an artifact expires:

* Its control coverage receives a lower assurance weighting
* Pending Changes are surfaced on the relationship to signal the gap
* If lifecycle management is enabled, VISO TRUST can automatically request updated documentation from the vendor

## Artifact Source Types

VISO TRUST tracks where each artifact came from:

| Source                             | Description                                                          |
| ---------------------------------- | -------------------------------------------------------------------- |
| **Collected from the client**      | Uploaded directly by your team                                       |
| **Publicly collected**             | Discovered from public sources (trust pages, websites, public repos) |
| **Collected from the third party** | Submitted by the vendor through the collection portal                |
| **Collected from VISO TRUST**      | Sourced from VISO TRUST's own evidence                               |

Source type is displayed in the artifact list and influences how the artifact is presented in the audit trail.

## Configuring Artifact Type Preferences

Org Admins can configure which artifact types to request by default in collection requests under **Settings → Assessments** (the **Required artifacts** section).

Whether publicly claimed compliance certifications count toward residual risk is a separate setting, managed under **Settings → Risk Model**.
