Compliance
The evidence a SOX walkthrough already asks for.
Every app your team builds with AI that touches the general ledger, AP, AR, or payroll is part of your control environment now, even if it isn't on anyone's list yet. Trustward's registry and audit trail are built to answer what a SOX walkthrough or a controls review actually tests: who can touch the financials, whether change to those systems is controlled, and whether you can prove it.
You sign the attestation. IT doesn't.
A risk committee can't verify controls in applications it can't enumerate, and most finance teams can't enumerate what their own people built with an AI tool last quarter. That gap sits inside the same control environment your auditor already tests every year. It just doesn't have a line item yet. Trustward gives it one.

The ITGC crosswalk
Mapped to what a SOX walkthrough tests.
Four domains carry a SOX IT general controls review. For each one, here's what Trustward gives an auditor today, and what's still ahead.
| Domain | What gets tested | What Trustward gives you |
|---|---|---|
| Access to programs and data | Who can touch financial data, and is access reviewed | The broker scopes every request to the rows and columns an app was granted, enforced in the database itself, beneath the app's own code. The registry is the access map: every app built in Trustward shows an owner and its granted scope. It covers what's built in Trustward; a scheduled re-review workflow for that access is still ahead. |
| Program changes | Are changes to those systems authorized, tested, and separated from the person who requested them | Every promotion runs through automated go-live checks (a build check, a dependency scan, a secret scan) that block automatically. It also carries a logged approval and a record of who promoted it. Deeper static-analysis scanning of the app's own code is on the roadmap. |
| Program development | Is the build-and-release process itself controlled | Apps build against stand-in data, then a proof run validates the finished app against real numbers before anything goes live. That flow runs today. Confirming every code path got exercised during build is still ahead. |
| Computer operations | Backup, job scheduling, incident handling | Inherited from the same cloud infrastructure your other systems already run on, and Trustward layers the access and change logs on top. Formal incident-response commitments and recovery targets are still being defined. |
The first two domains are where this pays off fastest. “Who can touch the financials, and how is change to those systems controlled” is usually the hardest question in the room. Here it's a direct export.
One export, mapped to the frameworks you answer to.
This is the same audit pack shown on the product tour: one click turns any app into a plain-language report your risk committee can sign. Underneath, it's a machine-readable export an auditor can test without touching the Trustward UI. It carries:
App inventory: owner, purpose, data classification, governance tier, lifecycle state.
Data-access lineage: which app read which columns from which source, source to dashboard.
The access log: every read, by app and builder identity, with scope, masking, and timestamp. Append-only and hash-chained, so an edited, deleted, or reordered row is detectable on verification.
Credential lifecycle: issuance, scope, and revocation events.
Approval record: who approved which data connection, when.
Change and deploy record: go-live check results, promotion events, and who promoted.
Decommission record: when access was revoked and the app's data store torn down.
Filtered and exported in one action, mapped to SOC 2, SOX, and GDPR control families.
Demonstrable today. Not certified yet.
Trustward is in private beta. We have not completed a SOC 2 audit or a SOX 404 attestation, and nothing on this page claims otherwise. What's above is what the product produces right now, mapped to the controls those frameworks test. A framework also tests operating effectiveness over a period, not just that a control exists on the day you looked. We can show you the control running; we can't yet show you twelve months of it running. We'll walk your controller and your external auditor through the live registry and export before you commit to anything.
Before diligence asks
A clean line item at exit, instead of an open question.
If a sponsor sits one level up, the apps your team builds with AI are already part of the control environment a buyer inspects at exit. Trustward gives the portfolio company a live inventory and an exportable access-and-change log for every app that ships through it, so “what is your team building, and who's watching the data” gets a straight answer. For the sponsor, it's the same view across the portfolio.
Questions before you forward this
What the audit side asks first.
Can my external auditor test this without your help?
Yes. The evidence bundle exports as machine-readable data mapped to control families, not a PDF built by our sales team.
Does this replace my SOC 2 or SOX audit?
No. It's the evidence your auditor tests against. The audit opinion is still theirs to render.
What if my framework isn't SOC 2 or SOX?
The same registry and access log support GDPR Article 30 records of processing and, where you're a regulated broker-dealer or adviser, FINRA books-and-records requests. Ask us about your specific framework.
What happens to this evidence if we stop using Trustward?
Ask us for an export before you decommission.