Artifact Permissions

Tanya Tandon Updated by Tanya Tandon

Understanding Artifact Source Types

This article explains the different artifact source based classifications and when each is used:

1. Collected from the Client

Definition

Used for any artifact that is:

  • Uploaded directly by the client, or
  • Added via the “+ Add Artifact to Assessment” button and provided by the client
Examples
  • Documents shared by the client over email
  • Documents retrieved from a trust center on behalf of the client (with an NDA in place)

2. Publicly Collected

Definition

Artifacts collected from publicly available sources.

Examples
  • Public trust centers
  • Company websites
  • Public compliance repositories

3. Collected from the Third Party

Definition

Artifacts that are:

  • Uploaded directly by the third party contact
  • Derived from questionnaire responses or sub-processor lists

How did we do?

Assessment Phases

Contact