SAMPLE / DEMO / SYNTHETIC

Public examples

Fictional Acme Cloud data only. These examples match the interactive Demo Center. They are not customer results, testimonials, or certifications.

No real customer, supporter, or confidential data appears on this page.

Evidence document example

Title: Access Control Policy (SAMPLE / DEMO / SYNTHETIC)

“Production access is restricted to named personnel and requires multi-factor authentication (MFA) for every session.”

Questionnaire example

Buyer asks (synthetic): Do you enforce multi-factor authentication for administrative access?

Formats Trustfill drafts against: SIG / CAIQ-style lists, Excel/CSV, TXT, or pasted questions. You still submit in the buyer’s portal after approval.

Supported answer with citation

Supported (cited)

How do you encrypt customer data at rest and in transit?

The synthetic policy states AES-256 encryption at rest and TLS 1.2 or stronger in transit.

Citation

Encryption Policy (SAMPLE / DEMO / SYNTHETIC)

All customer data stores are encrypted at rest using AES-256. All network traffic uses TLS 1.2 or stronger.

Multiple-source citation

Supported (cited)

Do you enforce multi-factor authentication for administrative access?

Yes. The synthetic Acme Cloud policies require MFA for administrative and production access, alongside named accounts and least-privilege RBAC.

  • Access Control Policy (SAMPLE / DEMO / SYNTHETIC)

    Production access is restricted to named personnel and requires multi-factor authentication (MFA) for every session.

  • Password and Authentication Policy (SAMPLE / DEMO / SYNTHETIC)

    MFA is required for all administrative access and for access to systems containing customer data.

Multi-source example. Human approval is still required before export.

UNVERIFIED example

UNVERIFIED

Do you hold a current ISO 27001 certification?

UNVERIFIED — the synthetic evidence vault contains no ISO 27001 certification evidence.

Trustfill does not invent a yes when evidence is missing.

Human-review example

Needs human review

How long are backups retained?

CONTRADICTION — the synthetic documents state both 35-day and 14-day daily-backup retention. A reviewer must resolve which source is authoritative before approval.

  • Data Retention Policy (SAMPLE / DEMO / SYNTHETIC)

    Daily backups are retained for 35 days. Monthly snapshots are retained for 12 months.

  • Legacy Backup Retention Standard (SAMPLE / DEMO / SYNTHETIC)

    Daily database backups are retained for 14 days. No monthly snapshots are retained under this legacy standard.

Conflict is surfaced, never silently merged into a compliance claim.

Export preview (synthetic)

Illustrative CSV-style rows after human decisions. Not a downloaded file.

question_id,status,answer_preview,citation_count
admin-mfa,approved,Yes. MFA required for admin access…,2
encryption,approved,AES-256 at rest; TLS 1.2+ in transit…,1
iso-27001,unverified,UNVERIFIED — no ISO 27001 evidence…,0
backup-retention,held,CONTRADICTION — reviewer resolving…,2
# SAMPLE / DEMO / SYNTHETIC — Acme Cloud

Try the full walkthrough

Interactive steps include evidence vault, upload, cite, UNVERIFIED, approve, and export.

Trust pages: Security · Privacy · FAQ · Terms