Can you prove what your security documentation says you’re doing?
ControlTrace connects requirements, implementation claims, policies, procedures, and evidence—helping teams identify potential assessment gaps before assessment begins.
Trace the requirement. Validate the claim. Find the gap.
Synthetic demo only. Do not upload CUI, classified, ITAR/export-controlled, sensitive government, client/employer-confidential, credential, secret, password, or production-log information.
Requirement
NIST SP 800-171 Rev. 2 · 3.1.1
Implementation
Privileged accounts are reviewed quarterly.
Policy
Found · Access Control Policy §4.2
Procedure
Conflict · Annual review language found
Evidence
Not identified among analyzed artifacts
Potential documentation gap
Policy support was found, but supporting evidence demonstrating the claimed account-review activity was not identified.
Evidence traceability, not a checklist
A supportable security story has a visible chain.
ControlTrace flags where the relationship between a requirement, documented claim, operating procedure, and execution evidence appears incomplete or inconsistent—then keeps a human reviewer in control.
EvidenceMap
Inspect the live chain from requirement to claim, policy, procedure, and evidence. Broken, conflicting, stale, and review-required relationships remain visible.
What the demo shows
ClaimCheck
Source-cited claims and their apparent support.
ConflictScan
Conflicting account-review frequencies for human review.
GapSignal
Prioritized potential gaps—not compliance determinations.
TraceScan Free
Start with the relationship analysis.
The synthetic workspace demonstrates the value in minutes: review a potential evidence gap, compare conflicting statements, and follow the trace back to its sources.
5
Trace relationships
3
Finding types
100%
Synthetic artifacts