Nucleus Systems Code Trust Assurance Framework
NS-CTAF
Measure, evidence, and certify software trust across code identity, integrity, secure development, supply chain, runtime behaviour, and governance.
Security tools find issues. NS-CTAF proves trust.
Organisations scan code. They still can’t prove software trust.
SolarWinds, Log4Shell, and XZ Utils showed that perimeter-only security fails when the threat originates in trusted software. Every dependency, pipeline, and AI-generated commit is a trust decision — and most organisations cannot demonstrate, continuously and with evidence, that those decisions are controlled.
NS-CTAF treats every stage of software production and distribution as an independently assessable trust boundary — producing a single, quantified Trust Score.
Find issues in code you already have.
Proves the whole system can be trusted.
Is a point-in-time snapshot.
Is a continuous, evidence-backed measure.
Six domains. Eighty-six controls.
NS-CTAF measures trust across the full software lifecycle — each domain weighted by its impact on overall software trust posture.
Identity & Provenance
Who wrote the code, and where it came from.
Integrity & Immutability
Whether builds and artifacts are tamper-proof.
Secure Development Practices
Whether secure engineering stops vulnerabilities at the source.
Dependency & Supply Chain
Whether third-party components are governed and controlled.
Runtime Behavior Assurance
Whether deployed software keeps behaving as expected.
Governance & Accountability
Whether ownership and policy sustain trust over time.
From evidence to a public trust signal
Assessment combines evidence, maturity scoring, automated tooling, and independent assessor validation.
Evidence
SBOMs, signing, scans, attestations, runtime and governance data collected and registered.
Assessment
86 controls scored across 5 axes, hard gates applied, evidence independently validated.
Output
Trust Score, domain scores, board report, and a prioritised 12-month roadmap.
Certification
A CTA-1 to CTA-4 certificate and a public Trust Registry listing.
Four levels of Code Trust Assurance
Based on the Trust Score and minimum domain thresholds — with seven hard gates that must pass regardless of overall score.
Transparent
45+ controls
The software supply chain is visible. SBOMs, basic scanning, dependency inventory, and ownership are in place.
Verified
63+ controls
Trust is backed by cryptographic evidence — artifact signing, build provenance, and automated security controls.
Assured
78+ controls
Trust is continuously measured across development, supply chain, runtime, and governance.
Adaptive Trust
86 / 86 controls
Trust is automated, continuously computed, self-healing, and independently verified.
Verify certified companies
A public directory where the market can verify certified companies by continent, country, sector, year, and certification level.
Verdex Technologies
Verdex Cloud Platform
Ironpath Software
Ironpath Delivery Suite
Solaris Build Systems
Solaris CI Cloud
Paxley Software
Paxley Core
Basic certificate verification is public. Certificate downloads, bulk checks, API verification, and full reports are available through Report Access bundles.
Verify a CertificateOne number the board understands
The 0–100 Trust Score summarises true code-trust posture across all six domains — mapped directly to certification readiness.
Aligned with the standards that matter
NS-CTAF maps to major software-security frameworks and regulations — so a single assessment addresses multiple compliance obligations.
Before you trust a vendor’s software, verify its code trust posture.
Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and 12-month roadmap.
