Encryption policy, enforced and evidenced.
“We encrypt everything” is a claim. Proving it means knowing which volumes, databases and queues are encrypted, which certificates expire next month, and whether the key-management policy approved last year matches what production actually does.
NIS2 requires policies and procedures on the use of cryptography and, where appropriate, encryption. TruSecure governs the claim: encryption coverage read from cloud and endpoint tooling, certificate lifecycles tracked, cryptographic policy versioned, approved by a named person and linked to the controls it documents.
How it works
- Define
The cryptographic policy is drafted from the control library, reviewed and approved by a named person, and versioned. Linked controls show where the policy is supposed to operate.
- Measure
Connectors read encryption-at-rest and in-transit coverage from cloud platforms and endpoint management, so the policy is measured against reality, not recited.
- Track
Certificate and key lifecycles are monitored. An expiring certificate surfaces as a gap with an owner and a date — before it becomes an outage.
- Prove
Coverage snapshots and policy approvals accumulate as evidence: the current state, the approved policy, and the history of both, in one place.
What encryption coverage looks like
- At rest
- 98.7% · 14 volumes open
- In transit
- TLS 1.2+ enforced
- Certificates
- 3 expiring ≤ 30 days
- Policy
- v3.2 · approved 2026-06-02
- Citations
- NIS2 21(2)(h) · ISO A.8.24
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Policies and procedures on cryptography and encryption | Art. 21(2)(h) |
| ISO 27001 | Rules for the effective use of cryptography, defined and implemented | A.8.24 |
| NIST CSF 2.0 | Data-at-rest and data-in-transit protections applied | PR.DS |
The cloud and MDM connectors read coverage directly from the platforms that enforce it — no manual attestation spreadsheet, and no quarter in which the answer silently drifts.
Cryptography is where governance most often meets “trust us, it is encrypted.” With coverage measured from source systems and the policy on the record, that conversation becomes a demonstration instead.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.