What Artifact Intelligence Does
When an artifact is submitted, Artifact Intelligence:- Classifies the document — identifies the artifact type (SOC 2 Type II, ISO 27001, penetration test, DPA, etc.)
- Extracts evidence — reads the document and identifies language that describes security controls and practices
- Maps to controls — matches extracted evidence to the relevant controls in your risk framework
- Assigns assurance — rates the confidence level of each detection based on the artifact type and evidence quality
- Identifies gaps — flags in-scope controls that aren’t addressed by the submitted evidence
Assurance Levels
Not all documents carry equal weight. Artifact Intelligence assigns an assurance level to each artifact based on how rigorous and trustworthy the evidence is.
Each artifact type’s own level is listed in-platform under Glossary → Artifact Types.
Assurance is also refined at the individual detection level. Evidence that only describes a control without testing it, evidence from an expired artifact, or evidence an auditor has manually downgraded all fall back to Limited assurance. Evidence from a presumed artifact is discounted below the level the real report would carry, because no document backs it. The risk analysis labels the reason next to the detection.
AI Assessment + Auditor Review
For assessments using the AI Assessment + Auditor Review method, Artifact Intelligence is supplemented by a VISO TRUST analyst who performs a focused review of high-assurance artifacts. Auditors look for things that require human judgment:- Qualified opinions or exceptions in SOC 2 reports
- Open critical or high findings in penetration test reports
- HITRUST validity dates and certification scope
- Subservice organizations and CUECs (complementary user entity controls) in SOC 2 reports
- Password-protected or confidential artifacts that require manual handling
AI analysis alone does not guarantee detection of every control in every artifact. For critical vendors or high-risk relationships, the AI Assessment + Auditor Review method provides the highest confidence in results.
What Happens After Analysis
Once analysis is complete:- Credited controls appear as Present in the risk analysis with the artifact as supporting evidence
- Control gaps appear as No Information — primary candidates for follow-up questionnaires or additional document requests
- The residual risk score updates to reflect the new evidence
- The artifact appears in the Artifacts tab with its classification, assurance level, and validity period
Artifact Validity
Every artifact has a validity period reflecting how long the document is considered current. SOC 2 reports typically cover a 12-month audit period; ISO 27001 certificates are valid for 3 years. Artifact Intelligence identifies the validity window during analysis and tracks expiration. When an artifact expires:- Its assurance drops to Limited, and detections from it are labeled Artifact expired
- Pending Changes are surfaced on the relationship
- If lifecycle management is enabled, VISO TRUST can automatically request a renewal from the vendor
Managing Artifacts
All artifacts for a relationship are visible in the Artifacts tab of the relationship detail page. From here you can:- View artifact classification, source, assurance level, and validity period
- Download artifacts
- Delete artifacts (subject to your role’s permissions)
- Add new artifacts at any time — even on an active or completed assessment
- Exclude artifacts from the risk analysis, or re-include ones previously excluded
Excluding Artifacts from Risk Analysis
Not every collected artifact belongs in the risk analysis. A document may be superseded by a newer one, duplicated, incomplete or unreadable, or irrelevant to the vendor or the assessment scope. Select the artifact in the Artifacts tab and select Exclude from analysis to remove it. Excluding an artifact removes its detections from the risk analysis, which can affect control coverage and risk calculations. The exclude dialog asks for a reason and an optional comment. Both are posted to the relationship’s activity feed, under Activity → All activity, so your team can see who excluded the artifact and why. Excluded artifacts are also left out of the assessment summary. The existing summary doesn’t update on its own: regenerate the assessment summary after excluding an artifact to see it removed there. Excluded artifacts stay in the artifact list. Use the Excluded artifacts visibility filter to find them, and select Include in analysis to bring one back into the risk analysis.Artifact Sources
The Source column in the artifact list labels each artifact as Public or Private:- Public — discovered by VISO TRUST through public research (trust pages, websites, other public sources)
- Private — everything else: artifacts uploaded by your team, submitted by the vendor through the collection portal, or sourced from VISO TRUST’s own evidence
Presumed Artifacts
When a vendor claims a compliance certification but no actual document has been collected, VISO TRUST creates a presumed artifact as a placeholder for that certification — for example, Presumed SOC 2 Type 2. Presumed artifacts give the claimed certification partial credit in the risk analysis until the real document arrives. In the artifact list, presumed artifacts:- Appear for all roles alongside regular artifacts, subject to the same filters
- Match the Presumed option in the Type filter menu — and only that option, so file artifact type filters like Third Party Audit exclude them
- Can’t be opened or downloaded, because there is no document behind them
- Show a Source tooltip identifying them as presumed from compliance certifications on the trust profile
- Show a discounted assurance level reflecting the partial credit the claimed certification earns in scoring — for example, a presumed SOC 2 Type 2 shows Limited assurance, below the level the real report would carry
If a Presumed Artifact Is Missing
Presumed artifacts are created automatically from compliance certifications on the vendor’s trust profile. You can’t add one manually. If a vendor claims a certification but no presumed artifact appears in the artifact list:- Check the Type filter in the Artifacts tab and select Presumed — presumed artifacts are excluded by file artifact type filters like Third Party Audit.
- Request the actual certification report through a collection request, or upload the document yourself from the Artifacts tab. A real artifact gives full credit and doesn’t depend on a presumed placeholder. See Attestations for how claimed certifications are upgraded to validated evidence.
- If the vendor’s certification is publicly verifiable and the presumed artifact still doesn’t appear, contact support@visotrust.com.