Read. Map. Propose. Approve.
The four-stage loop behind TruSecure's operational governance model. It runs continuously — every day, not in the six weeks before an audit — and every pass through the loop ends the same way: with a named person making a decision on the record.
The loop is what NIS2's management-accountability article (Art. 20) and DORA's management-body responsibility (Art. 5) look like when they are operational rather than aspirational: proposals are machine-cheap, but accountability stays human and attributable.
- Connect
Scoped, read-only connectors ingest state from SIEM/SOAR, ITSM, identity, cloud and MLOps tooling across nineteen integration categories. Nothing is re-keyed; the systems of record stay the systems of record.
- Map
AI reads the incoming state and classifies it against the shared control library — the same library every framework cites, so mapping happens once, not once per regulation.
- Propose
AI drafts control mappings, evidence summaries and gap flags as reviewable proposals, each with its source data attached so a reviewer can check the reasoning, not just the conclusion.
- Approve
A named, authenticated person approves, rejects or amends. That decision — not the AI output — is the record of truth, and it is sealed into the audit trail with identity and timestamp.
What a proposal looks like
Every proposal arrives with its provenance attached: which connector fed it, which control it maps to, which citation it satisfies, and what the AI is asking the reviewer to decide.
- Proposal
- PR-2026-0193
- Type
- Control mapping
- Control
- AC-2 · Accounts
- Citation
- NIS2 Art. 21(2)(i)
- Basis
- identity connector · 847 sign-in records
- Confidence
- review advised
- Decision
- pending — assigned to named reviewer
Human-Guided AI, Not Blind Automation
AI proposes. A named person decides. TruSecure's AI never autonomously approves a risk acceptance, marks a control compliant, or submits a regulatory report. The boundary is not a policy promise — it is drawn into the product:
- Reads
- Classifies
- Maps
- Summarizes
- Compares
- Drafts
- Proposes
- Approves a risk acceptance
- Marks a control compliant
- Submits a regulatory report
Routes to a named person
What the loop runs on
The Connect stage reads from the tools you already operate — identity, cloud platforms, endpoint management, SIEM/SOAR, ITSM, HR and more — through read-only connectors scoped to the minimum permission each evidence type requires. Premium connectors for the tools TruSecure resells carry the deepest coverage; marketplace and open-source connectors extend the tail.
The short answer
TruSecure operates on a four-stage loop: it connects to existing security and IT systems, uses AI to map incoming data against a shared control library, proposes drafts and flags for review, and requires a named human to approve any output that becomes an accountable decision.