Trust Center

Make boundaries, controls and responsibilities explicit.

How to examine trust in the system: first the boundaries, then the controls, then the responsibilities, then the evidence.

Security is not a blanket promise: it is a set of mechanisms whose scope and status can be examined separately, page by page.

Client

Question asked, data provided, final decision.

Imagine All The People environment

Processing, simulation, application controls and logging.

Required infrastructure and services

Execution foundation required by the selected configuration.

Three successive scopes: the client, the Imagine All The People environment, then the required infrastructure and services, separated by explicit boundaries.

Conceptual view. Exact components depend on the deployment configuration.
01Verify the details

Five questions. Five pages.

01Confidentialité

What data actually enters the system?

Data · Boundaries · Isolation

Confidentiality & isolation →

02Hosting

Where does the environment run?

Architecture · Location · Deployment

Hosting →

03Operations

What controls are actually operated?

Access · Encryption · Logging

Operational security →

04Governance

Which uses are accepted, reviewed or refused?

Uses · Review · Responsibility

Governance →

05Traceability

Which regulations may apply, and how should they be assessed?

Rules · Roles · Evidence

Regulatory traceability →

02Data & boundaries

The journey of a data item.

  1. Input
  2. Processing
  3. Simulation
  4. Result
  5. Retention / deletion
Overview. Details on data, boundaries and retention periods are provided on the Confidentiality page.

View confidentiality →

03Controls

Six families of controls.

Identity
Who has access, with what authentication.
Access
Which rights, over what scope.
Encryption
In transit and at rest.
Logging
What is recorded and retained.
Incidents
Detection, assessment, notification.
Recovery
Backup and recovery of the environment.

View the controls →

04Responsibilities

Security is never the responsibility of a single actor.

Data

Client

Selects the data provided.

Imagine All The People

Processes the data within the defined environment.

Infrastructure / third parties

Hosts the data according to the selected foundation.

Configuration

Client

Approves the selected scope.

Imagine All The People

Configures the environment and its controls.

Infrastructure / third parties

Provides the available technical options.

Operations

Client

Manages its own access.

Imagine All The People

Operates the application environment.

Infrastructure / third parties

Operates the underlying platform and its own safeguards.

Final decision

Client

Makes the decision and assumes responsibility for its use.

Imagine All The People

Provides a result, never a decision.

Infrastructure / third parties

Not applicable.

View governance →

05Evidence

What a client should be able to ask to examine.

  • Architecture description

  • Controls description

  • Data-flow description

  • Use-governance framework

  • Regulatory mapping by use case

Details of the available elements, their status and the conditions under which they can be shared are provided on the relevant pages.

06Limitations

Reducing risk does not eliminate risk.

  • Dedicated ≠ invulnerable

    A dedicated environment reduces exposure; it does not eliminate it.

  • Encrypted ≠ inaccessible

    Encryption protects against unauthorized access, not authorized access.

  • Auditable ≠ audited

    A mechanism that can be examined has not necessarily been examined by a third party.

  • Documented ≠ compliant by definition

    Compliance depends on the context of use, the actual data and the applicable contract.

Your next decision

Which decision do you want to explore?

Describe your need. We can point you to the right level of support.

What if you tested
your next decision?

State your decision. See the future it produces.

Explore the product