> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Artifact Intelligence

> Artifact Intelligence is VISO TRUST's AI engine that reads SOC 2, ISO 27001, and other security documents to extract control evidence and set assurance.

**Artifact Intelligence** is VISO TRUST's AI document analysis engine. It reads security and compliance documents, extracts evidence of security controls, and maps findings to your risk framework — automatically, in a fraction of the time a human analyst would take.

Every artifact processed in VISO TRUST — whether uploaded by you, submitted by a vendor, or discovered from public sources — passes through Artifact Intelligence.

## What Artifact Intelligence Does

When an artifact is submitted, Artifact Intelligence:

1. **Classifies the document** — identifies the artifact type (SOC 2 Type II, ISO 27001, penetration test, DPA, etc.)
2. **Extracts evidence** — reads the document and identifies language that describes security controls and practices
3. **Maps to controls** — matches extracted evidence to the relevant controls in your risk framework
4. **Assigns assurance** — rates the confidence level of each detection based on the artifact type and evidence quality
5. **Identifies gaps** — flags in-scope controls that aren't addressed by the submitted evidence

This process happens in seconds for most documents. The results appear directly in the assessment's risk analysis as credited controls, coverage metrics, and any remaining gaps.

## Assurance Levels

Not all documents carry equal weight. Artifact Intelligence assigns an **assurance level** to each artifact based on how rigorous and trustworthy the evidence is.

| Assurance Level | Description                                                                         | Examples                                                             |
| --------------- | ----------------------------------------------------------------------------------- | -------------------------------------------------------------------- |
| **Advanced**    | Rigorous independent third-party assessments with high confidence in implementation | ISO 27001, SOC 2 Type II, PCI DSS AOC/ROC, HITRUST r2                |
| **Standard**    | Third-party audited or externally validated, but narrower in scope                  | SOC 1 Type II, HITRUST i1                                            |
| **Moderate**    | Independent review of control design, or a lighter-weight certification             | SOC 2 Type I, SOC 1 Type I, HITRUST e1                               |
| **Limited**     | Self-attested or vendor-authored — useful for coverage but taken at face value      | Vendor questionnaires, privacy policies, security overview documents |

Each artifact type's own level is listed in-platform under **Glossary → Artifact Types**.

Assurance is also refined at the individual detection level. Evidence that only describes a control without testing it, evidence from an expired artifact, or evidence an auditor has manually downgraded all fall back to Limited assurance — the risk analysis labels the reason next to the detection.

## AI Assessment + Auditor Review

For assessments using the **AI Assessment + Auditor Review** method, Artifact Intelligence is supplemented by a VISO TRUST analyst who performs a focused review of high-assurance artifacts. Auditors look for things that require human judgment:

* **Qualified opinions or exceptions** in SOC 2 reports
* **Open critical or high findings** in penetration test reports
* **HITRUST validity dates** and certification scope
* **Subservice organizations and CUECs** (complementary user entity controls) in SOC 2 reports
* **Password-protected or confidential artifacts** that require manual handling

Auditor findings supplement AI detections — they don't replace them. If the AI detects a control as Present, an auditor may downgrade it to Not Present based on a qualified opinion. If the AI misses a relevant control, an auditor may add it.

<Note>
  AI analysis alone does not guarantee detection of every control in every artifact. For critical vendors or high-risk relationships, the AI Assessment + Auditor Review method provides the highest confidence in results.
</Note>

## What Happens After Analysis

Once analysis is complete:

* **Credited controls** appear as Present in the risk analysis with the artifact as supporting evidence
* **Control gaps** appear as No Information — primary candidates for follow-up questionnaires or additional document requests
* **The residual risk score** updates to reflect the new evidence
* **The artifact** appears in the Artifacts tab with its classification, assurance level, and validity period

If control gaps remain after analysis, VISO TRUST surfaces a **follow-up questionnaire** recommendation — allowing you to ask the vendor directly about specific controls that weren't addressed by submitted documents.

## Artifact Validity

Every artifact has a validity period reflecting how long the document is considered current. SOC 2 reports typically cover a 12-month audit period; ISO 27001 certificates are valid for 3 years. Artifact Intelligence identifies the validity window during analysis and tracks expiration.

When an artifact expires:

* Its assurance drops to Limited, and detections from it are labeled **Artifact expired**
* Pending Changes are surfaced on the relationship
* If lifecycle management is enabled, VISO TRUST can automatically request a renewal from the vendor

## Managing Artifacts

All artifacts for a relationship are visible in the **Artifacts tab** of the relationship detail page. From here you can:

* View artifact classification, source, assurance level, and validity period
* Download artifacts
* Delete artifacts (subject to your role's permissions)
* Add new artifacts at any time — even on an active or completed assessment

To correct a misclassified artifact type, go to **Trust → Artifact Intelligence** and change the artifact's **Artifact Type** there. The Trust section is available to Admins and Program Managers.

Artifacts are sourced from four origins:

* **Collected from the client** — uploaded by your team
* **Collected from the third party** — submitted by the vendor through the collection portal
* **Publicly collected** — discovered by VISO TRUST through public research
* **Collected from VISO TRUST** — sourced from VISO TRUST's own evidence
