Skip to content

bchetcuti/trust-surface-framework

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

26 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

TrustSurface Framework

A framework for making digital trust visible, assessable, and governable.

DOI Version Status Licence Website Security


What TrustSurface is

TrustSurface is a framework for understanding how digital systems shape stakeholder trust.

It helps organisations:

  • identify the systems through which digital trust is experienced
  • assess the observable trust signals those systems emit
  • understand digital trust posture through evidence rather than assurance language alone
  • govern trust posture through ownership, lifecycle, and transparency

TrustSurface focuses on the digital edge: the domains, services, dependencies, and signals through which trust is actually experienced.

It complements cybersecurity, risk, architecture, service, and vendor governance disciplines. It does not replace them.


Current release

Framework version: v1.1 public draft
Publication status: Public draft
Primary entry point: TSF-OVR-1 - Framework Overview


Normative boundary

The current normative framework set is:

Informative, Guidance, and Operational artefacts support this set but do not override it.


Core model

TrustSurface models digital trust through a connected chain:

Trust Surface domains → Trust Signals → Trust Signal Scorecard → Digital Trust Posture → Trust Surface Lifecycle → Governance Integration → Trust signalling and continuous improvement

The six-domain baseline is:

  1. Identity
  2. Domains & DNS
  3. Email Integrity
  4. Digital Services
  5. Infrastructure & Platforms
  6. Third-Party Ecosystem

Repository structure

trust-surface-framework/
├── README.md
├── docs/
│   ├── 01-start-here/          Framework overview, one-page specification
│   ├── 02-core-framework/      Normative and core informative artefacts
│   ├── 03-application/         Assessment method, examples, adoption guidance
│   ├── 04-publication-control/ Document register, versioning, citation, licence
│   └── 05-narrative/           Origin and context
└── artefacts/
    └── diagrams/               Controlled SVG diagrams (TSF-01 through TSF-08)

Recommended reading order

  1. TSF-OVR-1 - Framework Overview
  2. TSF-PRI-1 - Trust Principles
  3. TSF-DEF-1 - Trust Surface Definition
  4. TSF-MOD-1 - Trust Surface Model & Domains
  5. TSF-SIG-1 - Trust Signal Catalogue
  6. TSF-LIF-1 - Trust Surface Lifecycle
  7. TSF-GOV-1 - Governance Integration Model
  8. TSF-MTH-1 - Assessment Method
  9. TSF-MAT-1 - Digital Trust Maturity Model

Application artefacts


Publication control


What TrustSurface is not

TrustSurface is not:

  • a replacement for cybersecurity frameworks
  • a full attack surface management model
  • a purely brand or communications-based trust method
  • a product-specific implementation standard
  • a claim that digital trust can be reduced to one single number without interpretation

It is a framework for making digital trust visible, assessable, and governable over time.


Licence

TrustSurface Framework content is licensed under Creative Commons Attribution 4.0 International (CC BY 4.0).


Citation

Chetcuti, Bryan. (2026). TrustSurface Framework (v1.1 public draft). trustsurface.org.

See TSF-CIT-1 for full citation and attribution guidance.


Contributing

Feedback and contributions are welcome. See TSF-CNS-1 - Consultation & Contribution Guidance.


Security

See TSF-SEC-1 - Security & Vulnerability Disclosure.

About

TrustSurface is an open framework for understanding and governing digital trust signals across systems, services, and organisations.

Topics

Resources

Stars

Watchers

Forks

Contributors