The governed evidence repository.
Search documents and machine evidence with the context an audit needs: source authority, version, checksum, freshness, sensitivity, reviewer decision, control mappings, custody events, and package eligibility. This public surface uses synthetic reference records; protected projects keep client evidence behind workspace verification.
Trace one artifact from source authority to release boundary.
Select any node to isolate upstream provenance and downstream impact. This interactive synthetic reference models how protected workspaces can resolve the same lineage against tenant-scoped evidence.
synthetic reference trace
Bind proof to context
Capture, source context, validation, redaction state, and custody stay one record.
- Before
- 2
- After
- 5
- State
- verified
Projected reuse remains reviewable; it is never treated as an automatic conclusion.
Documents, configurations, and runtime proof
Representative repository objects show the metadata and review posture that remain attached from collection through package release.
| Artifact | Source | Captured | Freshness | Review | Maps | Digest |
|---|---|---|---|---|---|---|
consent-confirmation-event.json EV-2048 · Runtime event | Enrollment API | 18 min ago | Current | Accepted | 6 | 8df1…a43c |
approved-consent-notice.pdf EV-2047 · Document | Document repository | 2 hr ago | Current | Accepted | 9 | 37c0…1f92 |
consent-persistence-check.json EV-2046 · API assertion | Enrollment API | 3 hr ago | Current | Accepted | 4 | 1ac4…7bb0 |
enrollment-consent-session.zip EV-2045 · Browser workflow proof | Enrollment application | 1 day ago | Review required | Redaction hold | 3 | c91e…0d18 |
Project instances use reusable evidence contracts
Capture bounded synthetic request/response records and bind them to source-native requirements.
Retain approved document versions, effective dates, ownership, and review history as one governed record.
Model screenshot, action, and page-state custody while holding sensitive output for review.
Reference projects can guide the evidence format, but ControlFrame evidence must come from ControlFrame collector runs or explicit auditor-safe uploads. Placeholder slots stay visible and honest.
Native requirement identifiers stay first-class
CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements.
The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.
The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.