SaaS Trust & Service Compliance Management

BC-4290 Level 1 Software & Technology 2 providers 2 API surfaces

Service-level attestations, customer security questionnaires, public trust disclosures, sub-processor management, service-privacy commitments, and customer-facing service-resilience commitments for the SaaS offering.

SaaS Trust & Service Compliance Management (BC-4290) is a level-1 business capability in the Software & Technology model. The catalog holds 2 API surface(s) from 2 provider(s) that can perform some part of it. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.

Where this capability definition comes from. This capability is part of a published business-architecture model that API Evangelist did not author. It is redistributed here under CC-BY-4.0. Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 Changes: Consolidated from 333 per-L1 YAML files into one JSON; English only (upstream i18n/ omitted); descriptions whitespace-normalised. No capability was added, removed, renamed or re-parented. Source repository · NOTICE and third-party framework attributions

Authorities this capability cites

Cited by the capability model itself. These frameworks are referenced, never redistributed, and citing one does not imply its owner endorses this listing.

Sub-capabilities

Service Attestation Management BC-4290.10

Coordination of service-level attestations such as SOC 2, ISO 27001, and FedRAMP for the SaaS offering.

no catalog coverage

Customer Security Questionnaire Management BC-4290.20

Stewardship of the questionnaire repository, response authoring, and knowledge base used to answer customer vendor-risk assessments.

no catalog coverage

Trust Portal & Public Disclosure BC-4290.30

Operation of the customer trust portal, public status disclosures, and document distribution workflows.

2 providers, 2 API surfaces

Sub-Processor Management BC-4290.40

Inventory, disclosure, and change-notification of sub-processors that handle customer data.

no catalog coverage

Service Privacy Commitment Management BC-4290.50

Stewardship of data-processing addenda, customer data-flow disclosures, and routing of data-subject requests.

no catalog coverage

Service Resilience Commitment Management BC-4290.60

Customer-facing service-level commitments, uptime disclosure, and service-credit administration.

no catalog coverage

Providers that reach this capability

Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.

This page carries no rating. Capabilities are not rated. A capability is a description of what a business does, not a thing a company publishes, so a Kin Score would have nothing to measure.
The edge table is a Pro feature. This page shows which providers and tags reach SaaS Trust & Service Compliance Management. The underlying tag → capability edges — each with the quoted fragment of the provider's own OpenAPI that evidences it, a calibrated confidence score, and the contract-provenance gate it passed — are available through the API, along with company-level capability maps. Only edges at confidence ≥ 0.7 with evidence found verbatim in the source contract are published at all.

See plans →  ·  How the edges are graded →