Skip to main content
Artifact Intelligence is VISO TRUST’s AI document analysis engine. It reads security and compliance documents, extracts evidence of security controls, and maps findings to your risk framework — automatically, in a fraction of the time a human analyst would take. Every artifact processed in VISO TRUST — whether uploaded by you, submitted by a vendor, or discovered from public sources — passes through Artifact Intelligence.

What Artifact Intelligence Does

When an artifact is submitted, Artifact Intelligence:
  1. Classifies the document — identifies the artifact type (SOC 2 Type II, ISO 27001, penetration test, DPA, etc.)
  2. Extracts evidence — reads the document and identifies language that describes security controls and practices
  3. Maps to controls — matches extracted evidence to the relevant controls in your risk framework
  4. Assigns assurance — rates the confidence level of each detection based on the artifact type and evidence quality
  5. Identifies gaps — flags in-scope controls that aren’t addressed by the submitted evidence
This process happens in seconds for most documents. The results appear directly in the assessment’s risk analysis as credited controls, coverage metrics, and any remaining gaps.

Assurance Levels

Not all documents carry equal weight. Artifact Intelligence assigns an assurance level to each artifact based on how rigorous and trustworthy the evidence is. Each artifact type’s own level is listed in-platform under Glossary → Artifact Types. Assurance is also refined at the individual detection level. Evidence that only describes a control without testing it, evidence from an expired artifact, or evidence an auditor has manually downgraded all fall back to Limited assurance. Evidence from a presumed artifact is discounted below the level the real report would carry, because no document backs it. The risk analysis labels the reason next to the detection.

AI Assessment + Auditor Review

For assessments using the AI Assessment + Auditor Review method, Artifact Intelligence is supplemented by a VISO TRUST analyst who performs a focused review of high-assurance artifacts. Auditors look for things that require human judgment:
  • Qualified opinions or exceptions in SOC 2 reports
  • Open critical or high findings in penetration test reports
  • HITRUST validity dates and certification scope
  • Subservice organizations and CUECs (complementary user entity controls) in SOC 2 reports
  • Password-protected or confidential artifacts that require manual handling
Auditor findings supplement AI detections — they don’t replace them. If the AI detects a control as Present, an auditor may downgrade it to Not Present based on a qualified opinion. If the AI misses a relevant control, an auditor may add it.
AI analysis alone does not guarantee detection of every control in every artifact. For critical vendors or high-risk relationships, the AI Assessment + Auditor Review method provides the highest confidence in results.

What Happens After Analysis

Once analysis is complete:
  • Credited controls appear as Present in the risk analysis with the artifact as supporting evidence
  • Control gaps appear as No Information — primary candidates for follow-up questionnaires or additional document requests
  • The residual risk score updates to reflect the new evidence
  • The artifact appears in the Artifacts tab with its classification, assurance level, and validity period
If control gaps remain after analysis, VISO TRUST surfaces a follow-up questionnaire recommendation — allowing you to ask the vendor directly about specific controls that weren’t addressed by submitted documents.

Artifact Validity

Every artifact has a validity period reflecting how long the document is considered current. SOC 2 reports typically cover a 12-month audit period; ISO 27001 certificates are valid for 3 years. Artifact Intelligence identifies the validity window during analysis and tracks expiration. When an artifact expires:
  • Its assurance drops to Limited, and detections from it are labeled Artifact expired
  • Pending Changes are surfaced on the relationship
  • If lifecycle management is enabled, VISO TRUST can automatically request a renewal from the vendor

Managing Artifacts

All artifacts for a relationship are visible in the Artifacts tab of the relationship detail page. From here you can:
  • View artifact classification, source, assurance level, and validity period
  • Download artifacts
  • Delete artifacts (subject to your role’s permissions)
  • Add new artifacts at any time — even on an active or completed assessment
  • Exclude artifacts from the risk analysis, or re-include ones previously excluded
To correct a misclassified artifact type, go to Trust → Artifact Intelligence and change the artifact’s Artifact Type there. The Trust section is available to Admins and Program Managers.

Excluding Artifacts from Risk Analysis

Not every collected artifact belongs in the risk analysis. A document may be superseded by a newer one, duplicated, incomplete or unreadable, or irrelevant to the vendor or the assessment scope. Select the artifact in the Artifacts tab and select Exclude from analysis to remove it. Excluding an artifact removes its detections from the risk analysis, which can affect control coverage and risk calculations. The exclude dialog asks for a reason and an optional comment. Both are posted to the relationship’s activity feed, under Activity → All activity, so your team can see who excluded the artifact and why. Excluded artifacts are also left out of the assessment summary. The existing summary doesn’t update on its own: regenerate the assessment summary after excluding an artifact to see it removed there. Excluded artifacts stay in the artifact list. Use the Excluded artifacts visibility filter to find them, and select Include in analysis to bring one back into the risk analysis.

Artifact Sources

The Source column in the artifact list labels each artifact as Public or Private:
  • Public — discovered by VISO TRUST through public research (trust pages, websites, other public sources)
  • Private — everything else: artifacts uploaded by your team, submitted by the vendor through the collection portal, or sourced from VISO TRUST’s own evidence
The icon, tooltip, and Source filter all reflect this same Public/Private distinction. Private artifacts show a lock icon. Sorting the Source column still groups artifacts by who provided them, so vendor-submitted and team-uploaded artifacts stay separated even though both are labeled Private.

Presumed Artifacts

When a vendor claims a compliance certification but no actual document has been collected, VISO TRUST creates a presumed artifact as a placeholder for that certification — for example, Presumed SOC 2 Type 2. Presumed artifacts give the claimed certification partial credit in the risk analysis until the real document arrives. In the artifact list, presumed artifacts:
  • Appear for all roles alongside regular artifacts, subject to the same filters
  • Match the Presumed option in the Type filter menu — and only that option, so file artifact type filters like Third Party Audit exclude them
  • Can’t be opened or downloaded, because there is no document behind them
  • Show a Source tooltip identifying them as presumed from compliance certifications on the trust profile
  • Show a discounted assurance level reflecting the partial credit the claimed certification earns in scoring — for example, a presumed SOC 2 Type 2 shows Limited assurance, below the level the real report would carry
The discounted level appears everywhere the artifact’s assurance is shown: the artifact list, the risk analysis, the trust profile, and report exports. It matches the assurance the risk model actually applies when scoring controls. In risk analysis, detections from a presumed artifact are titled with the audit report type followed by Attestation — for example, SOC 2 Type 2 Attestation. The card shows no quoted passage, and its Compliance attestation badge carries a tooltip explaining that the control is likely present based on evidence of compliance certification. The assurance meter labels the downgrade Presumed certification. If the artifact is also expired or manually reduced, that stronger reason is shown instead. When a real artifact of the same audit type is added, it supersedes the presumed artifact automatically. If that real artifact is later removed, the presumed artifact is restored.

If a Presumed Artifact Is Missing

Presumed artifacts are created automatically from compliance certifications on the vendor’s trust profile. You can’t add one manually. If a vendor claims a certification but no presumed artifact appears in the artifact list:
  1. Check the Type filter in the Artifacts tab and select Presumed — presumed artifacts are excluded by file artifact type filters like Third Party Audit.
  2. Request the actual certification report through a collection request, or upload the document yourself from the Artifacts tab. A real artifact gives full credit and doesn’t depend on a presumed placeholder. See Attestations for how claimed certifications are upgraded to validated evidence.
  3. If the vendor’s certification is publicly verifiable and the presumed artifact still doesn’t appear, contact support@visotrust.com.