> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Artifact Intelligence

> Artifact Intelligence is VISO TRUST's AI engine that reads SOC 2, ISO 27001, and other security documents to extract control evidence and set assurance.

**Artifact Intelligence** is VISO TRUST's AI document analysis engine. It reads security and compliance documents, extracts evidence of security controls, and maps findings to your risk framework — automatically, in a fraction of the time a human analyst would take.

Every artifact processed in VISO TRUST — whether uploaded by you, submitted by a vendor, or discovered from public sources — passes through Artifact Intelligence.

## What Artifact Intelligence Does

When an artifact is submitted, Artifact Intelligence:

1. **Classifies the document** — identifies the artifact type (SOC 2 Type II, ISO 27001, penetration test, DPA, etc.)
2. **Extracts evidence** — reads the document and identifies language that describes security controls and practices
3. **Maps to controls** — matches extracted evidence to the relevant controls in your risk framework
4. **Assigns assurance** — rates the confidence level of each detection based on the artifact type and evidence quality
5. **Identifies gaps** — flags in-scope controls that aren't addressed by the submitted evidence

This process happens in seconds for most documents. The results appear directly in the assessment's Risk Analysis tab as credited controls, coverage metrics, and any remaining gaps.

## Assurance Levels

Not all documents carry equal weight. Artifact Intelligence assigns an **assurance level** to each artifact based on how rigorous and trustworthy the evidence is.

| Assurance Level | Description                                                                                                      | Examples                                                          |
| --------------- | ---------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| **Advanced**    | Rigorous independent third-party assessments with high confidence in implementation                              | SOC 2 Type II, ISO 27001, FedRAMP High, CSA STAR Level 2, HITRUST |
| **Standard**    | Third-party audited or externally validated, but narrower in scope                                               | SOC 2 Type I, PCI DSS AOC, penetration test reports               |
| **Moderate**    | Structured evidence with partial validation — stronger than a narrative policy, without a full independent audit | Completed security questionnaires, compliance self-attestations   |
| **Limited**     | Self-attested or vendor-authored — useful for coverage but taken at face value                                   | Security policies, security overview documents, self-assessments  |

Assurance is also refined at the individual control level — a high-assurance artifact that only partially addresses a control will have a lower per-control assurance than one that addresses it comprehensively.

## AI Assessment + Auditor Review

For assessments using the **AI Assessment + Auditor Review** method, Artifact Intelligence is supplemented by a VISO TRUST analyst who performs a focused review of high-assurance artifacts. Auditors look for things that require human judgment:

* **Qualified opinions or exceptions** in SOC 2 reports
* **Open critical or high findings** in penetration test reports
* **HITRUST validity dates** and certification scope
* **Subservice organizations and CUECs** (complementary user entity controls) in SOC 2 reports
* **Password-protected or confidential artifacts** that require manual handling

Auditor findings supplement AI detections — they don't replace them. If the AI detects a control as Present, an auditor may downgrade it to Not Present based on a qualified opinion. If the AI misses a relevant control, an auditor may add it.

<Note>
  AI analysis alone does not guarantee detection of every control in every artifact. For critical vendors or high-risk relationships, the AI Assessment + Auditor Review method provides the highest confidence in results.
</Note>

## What Happens After Analysis

Once analysis is complete:

* **Credited controls** appear as Present in the Risk Analysis tab with the artifact as supporting evidence
* **Control gaps** appear as No Info or Unvalidated — primary candidates for follow-up questionnaires or additional document requests
* **The residual risk score** updates to reflect the new evidence
* **The artifact** appears in the Artifacts tab with its classification, assurance level, and validity period

If control gaps remain after analysis, VISO TRUST surfaces a **follow-up questionnaire** recommendation — allowing you to ask the vendor directly about specific controls that weren't addressed by submitted documents.

## Artifact Validity

Every artifact has a validity period reflecting how long the document is considered current. SOC 2 reports typically cover a 12-month audit period; ISO 27001 certificates are valid for 3 years. Artifact Intelligence identifies the validity window during analysis and tracks expiration.

When an artifact approaches expiration:

* Its assurance level is progressively reduced
* Pending Changes are surfaced on the relationship
* If lifecycle management is enabled, VISO TRUST can automatically request a renewal from the vendor

## Managing Artifacts

All artifacts for a relationship are visible in the **Artifacts tab** of the relationship detail page. From here you can:

* View artifact classification, source, assurance level, and validity period
* Correct a misclassification (available to users assigned to the relationship and Org Admins)
* Download artifacts
* Delete artifacts (subject to your role's permissions)
* Add new artifacts at any time — even on an active or completed assessment

Artifacts are sourced from four origins:

* **Collected from the client** — uploaded by your team
* **Collected from the third party** — submitted by the vendor through the collection portal
* **Publicly collected** — discovered by VISO TRUST through public research
* **Collected from VISO TRUST** — sourced from VISO TRUST's own evidence
