Trust & Verification
Don't take our word for it.
Check.
FrameworkMapper's scoring is deterministic, its methodology is published, its certificates verify publicly, and its model changes are committed by cryptographic hash. This page collects every way you — or your auditor — can verify what we claim.
Model commitments you can hash
The UCPA scoring model is committed by published SHA-256 hashes — the model definition itself, not just the weights. If we ever change how priorities are computed, the hash changes, and anyone can detect it. One scoring engine runs server-side for every report, so no two views of your data can disagree.
See the published commitments →Certificates anyone can verify
Every assessment certificate carries a tamper-evident verification hash computed from its issuance fields and stored immutably. A procurement officer, insurer, or auditor can confirm authenticity in seconds — no account, no phone call. Altered certificates fail the check.
Verify a certificate →AI transparency, in writing
We document exactly where AI is used (tool research, mapping classification, narrative prose) and where it is never used: UCPA scores, TTI scores, coverage math, threat-actor data — any numeric output you see. Buyers who must attest that AI isn't making scoring decisions can point to this page and ours.
Read the AI transparency statement →Encryption that assumes breach
Assessment data is protected with envelope encryption — a per-organization data key wrapped by a key that never touches the database. Exported backups use AES-256-GCM with Argon2id key derivation combined with a server-held key, so a stolen backup file can't be brute-forced offline. Incident-response contacts are encrypted under your organization's own key.
Security details in our Privacy Policy →Threat intelligence with named sources
Every threat actor, technique prevalence, and sector amplifier traces to a source you can read yourself: CISA advisories and KEV, MITRE ATT&CK® and CTID mappings, the Verizon DBIR, MS-ISAC reporting. We publish which feeds we use, which we declined, and why. We do not invent threat data.
Browse the Threat Library →Vendors can't pay for scores
The Tool Trust Index draws only on independent registries — CISA KEV, FedRAMP/GovRAMP, NIST CMVP, CSA STAR, and tier-1 analyst placements. No vendor self-attestation is accepted, the KEV signal cannot be disabled by anyone, and sponsorship never changes a score, a mapping, or a recommendation.
How TTI works →What we deliberately don't claim
Coverage means capability, not proof. When our tools say a control is "covered," that means a tool in your stack is capable of addressing it — not that it's configured and operating. The assessment is where you establish what's actually in place, and every coverage figure we show carries that disclosure.
A certificate is a record, not a regulatory credential. FrameworkMapper certificates document a completed assessment. They do not substitute for a C3PAO CMMC certification, a FedRAMP/GovRAMP authorization, or a HIPAA attestation — and we say so on the certificate page.
Compliance is your responsibility. FrameworkMapper measures, prioritizes, and documents. It does not implement controls on your systems, and using it does not by itself make you compliant with anything.