The Trust Systems Assurance Method (TSAM) is a registry-agnostic methodology for designing, assessing, and operating trust-bearing distributed systems.
TSAM defines how governance intent, assurance levels, conformance verification, runtime integrity controls, and evidence production are bound into a coherent assurance architecture.
TSAM is not a standard and not a certification program.
TSAM is a method for making trust systems testable, observable, and upgradeable.
This repository uses the key words MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL as described in RFC 2119 and RFC 8174.
TSAM applies to systems that:
TSAM is registry-agnostic and protocol-agnostic.
A TSAM-aligned system MUST:
TSAM structures assurance across five layers:
Implementations MAY distribute these layers across multiple repositories or artifacts, but MUST preserve coherence across them.
This repository implements components aligned with TSAM.
TSAM provides the methodological spine.
The repository provides a concrete instantiation.