Skip to content
ScoRISKTrust IntelligenceRequest early accessRequest early access
Compliance

The six regulations people ask us about.

Each one mapped to the specific TrustMark capability that satisfies it — the challenge in plain terms, and what we actually do about it. The other 12 frameworks live in the full register.

Talk to us about your filingBrowse all 18 →Read the DSA case study
EUShips today

EmpCo Directive

From 27 September 2026, environmental claims made to EU consumers must be substantiated before publication, and generic claims such as “climate neutral” based on offsetting are banned outright.

How TrustMark helps✓Per-claim pass/fail with the evidence attached✓Independence check on every substantiating source✓A dossier that survives a regulator reading it line by line
UKPartial today

DMCC Act

The CMA can now fine directly for misleading environmental claims and for fake or incentivised reviews — up to 10% of global turnover, without going to court first.

How TrustMark helps✓Green-claim substantiation in CMA-facing form✓Review-integrity verification across listings✓One evidence trail covering both exposures
USShips today

FTC §5 substantiation

Advertising claims must be substantiated at the time they are made. “Operation AI Comply” has made unsupported AI and performance claims an active enforcement priority.

How TrustMark helps✓Claim-by-claim substantiation records✓Source independence and tier scored per claim✓Reproducible dossier if the FTC asks how you knew
EUPartial today

Digital Services Act

In-scope platforms must assess and mitigate systemic risks under Articles 34 and 35, and hand an independent auditor evidence that the mitigations work under Article 37.

How TrustMark helps✓Article 34/35 risk-assessment evidence✓Discrepancy analysis against platform self-reports✓Reproducible re-scoring for Article 37 audits
EU · GlobalPartial today

AML framework & FATF

Adverse-media screening and enhanced due diligence both depend entirely on how reliable the underlying sources are — a judgement most EDD files record as a hyperlink.

How TrustMark helps✓Adverse-media hits with scored source credibility✓An EDD case-file annex, not a link dump✓Conflicting-information detection across languages
EUShips today

NIS2 Directive

Incident reporting duties mean security teams act on external threat intelligence of uneven quality, often under a 24-hour initial notification clock.

How TrustMark helps✓Source vetting before intelligence drives a decision✓Incident-disinformation case files✓Conflicting threat reports flagged, not averaged
Case studyDigital Services ActEuropean Union · 1 of 18 in the register
The obligation

The filing — and the audit of the filing.

The DSA asks a platform to assess its systemic risks, show what it did about them, and then let an independent auditor check the work. Two sides, one evidence trail. Below is the mapping we actually ship — published, not described.

6%of global turnover at stakeArt. 37audits run yearly
Case filePartial
InstrumentRegulation (EU) 2022/2065Enforced byEuropean Commission · national Digital Services CoordinatorsIn forceFully applicable since 17 Feb 2024We coverArt. 17 · 34 · 35 · 37 · 42ArtefactReplayable evidence report per claim
How a filing gets built

Ingest the record

Every moderation action, appeal and statement of reasons lands in the claim registry with its source attached.

Score the risk

Illegal-content and disinformation exposure scored per claim across all five dimensions — Article 34, quantified.

Evidence the mitigation

Each measure is tied to the risk it answers and the scored claims that show whether it moved the number.

Hand it to the auditor

A versioned snapshot the Article 37 auditor replays end to end — same inputs, same weights, same number.

An auditor doesn’t want your conclusion. They want to arrive at it themselves.

Why the trail is the product
Two readers, one trail
For platforms · VLOPs

An internal compliance engine

Run systemic-risk assessments, document your mitigations, and generate audit-ready reports that show your work under Articles 34 & 35.

✓Quantify illegal-content & disinformation risk✓Evidence your mitigation measures✓Export audit-ready risk assessment reports
For regulators · auditors

An independent verification oracle

Re-run a platform sample through the same scoring and proof chain, then compare against its self-reported metrics — reproducible evidence for Article 37 audits.

✓Re-score any sample, reproducibly✓Compare against platform self-reports✓Replay every score from its proof chain
Obligation → capabilityPartial coverage
ArticleWhat it obliges you to doCapability shipping today
17Statements of reasons for every moderation decisionProof chain · full audit trail
34(1)(a)Illegal-content & disinformation riskClaim Registry · CRV
34(1)(b)Fundamental-rights impactsSource Integrity · SIV
34(2)Recommender-system amplificationRhetorical signals · RSV
35(1)(k)Marking AI-generated mediaVisual authenticity · VFV
37Independent audit evidenceProof chain + exports
These are the obligations we cover today. The register grades DSA overall as partial — we don’t claim the articles that aren’t listed here.See DSA in the register →
The deliverable

What lands in the transparency report.

Every figure below traces back to scored claims with their full proof chain attached — an auditor can pull any number apart and replay it.

Illustrative figures
0.2%Illegal-content rate
1,284Electoral disinformation · debunked
323Public-health misinfo · disputed
+42%Recommender amplification vs baseline
✓Versioned prompts, formulas and snapshots✓Every figure replayable from its proof chain✓Exportable in the shape an auditor expects
Scope boundary
What we don’t claim

The parts of the DSA we leave to someone else.

–Article 40 researcher data access — a platform-side data pipeline, not a scoring problem.–Trusted-flagger intake and notice-and-action ticketing workflows.–Ad-repository hosting and recommender-system configuration disclosures.
Where it lands

Bring us the article you have to answer for.

We’ll show you the claims, the sources and the weights behind every figure you’d file — and what we’d still leave to you.

End of case studyThe other 12 frameworks are graded in the register.Open the register →
The full register

12 more frameworks, searchable and honestly graded.

Green claims, fake reviews, endorsements, systemic risk, adverse media, market abuse — filter by region and status, and open any row for the deliverable behind it.

Open the register →
10Ship today
7Partial
1On the roadmap
5Jurisdictions
Beyond compliance

TrustMark™ is not a legal compliance platform.

It is a trust intelligence platform that helps organizations strengthen governance by providing measurable, explainable, and evidence-based trust assessments.

Rather than determining what is true or false, TrustMark™ lets you understand how much confidence you can place in digital information — and demonstrate that your decisions are transparent, documented, and defensible.

Trust intelligence for the next generation of digital governance.

Early access

ScoRISK is in private preview.

Two required fields to get in the queue — the rest is optional and helps us tailor your access.

No spam, ever — we review every requestAll five TrustMark dimensions, liveEarly access shapes what we build next
Flexible credit-based pricing — details at early access.

We’ll email you within a few days. Nothing is shared with anyone.