Skip to main content
Evidence operations

The governed evidence repository.

Search documents and machine evidence with the context an audit needs: source authority, version, checksum, freshness, sensitivity, reviewer decision, control mappings, custody events, and package eligibility. This public surface uses synthetic reference records; protected projects keep client evidence behind workspace verification.

Catalog-backed regimes
6
78 roadmap or planned
Reference workspace
1
Standalone synthetic model
Source-native rows
2
Synthetic CMS evidence mappings
Review holds
1
Held for a redaction decision
Evidence lineage

Trace one artifact from source authority to release boundary.

Select any node to isolate upstream provenance and downstream impact. This interactive synthetic reference models how protected workspaces can resolve the same lineage against tenant-scoped evidence.

synthetic reference trace

03Governed object

Bind proof to context

Capture, source context, validation, redaction state, and custody stay one record.

EV-2048
Before
2
After
5
State
verified

Projected reuse remains reviewable; it is never treated as an automatic conclusion.

Artifact registry

Documents, configurations, and runtime proof

Representative repository objects show the metadata and review posture that remain attached from collection through package release.

4 synthetic objects · 22 control mappings
ArtifactSourceCapturedFreshnessReviewMapsDigest
consent-confirmation-event.json
EV-2048 · Runtime event
Enrollment API18 min agoCurrentAccepted68df1…a43c
approved-consent-notice.pdf
EV-2047 · Document
Document repository2 hr agoCurrentAccepted937c0…1f92
consent-persistence-check.json
EV-2046 · API assertion
Enrollment API3 hr agoCurrentAccepted41ac4…7bb0
enrollment-consent-session.zip
EV-2045 · Browser workflow proof
Enrollment application1 day agoReview requiredRedaction hold3c91e…0d18
Collector design
API contract evidence

Capture bounded synthetic request/response records and bind them to source-native requirements.

Document authority evidence

Retain approved document versions, effective dates, ownership, and review history as one governed record.

Browser workflow evidence

Model screenshot, action, and page-state custody while holding sensitive output for review.

Evidence rule

Reference projects can guide the evidence format, but ControlFrame evidence must come from ControlFrame collector runs or explicit auditor-safe uploads. Placeholder slots stay visible and honest.

Framework registry

Native requirement identifiers stay first-class

ARC-AMPE
v1.02
Beta

CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.

ACATAU
NIST SP 800-53
Rev. 5, Release 5.2.0
Beta

NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements.

ACATAU
CMS Enhanced Direct Enrollment
Year 9 (PY 2026–PY 2027)
Beta

The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.

Application UIAPI FITLanguage access
HIPAA Security Rule
45 CFR Part 164 Subparts A and C
Beta

The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

Administrative safeguardsPhysical safeguardsTechnical safeguards
HITRUST CSF
v11.8.0
Roadmap

A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

Information protection programAccess controlEndpoint protection
SOC 2
2017 TSC (revised points of focus, 2022)
Beta

Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

SecurityAvailabilityConfidentiality
Evidence Workspaces | ControlFrame