— The assessor engine

The hard part, built in.

A real assessment is more than a pass/fail scan. It scores every control for maturity, reviews and accepts each piece of evidence, turns every gap into a corrective action plan with an owner and a due date, and produces a signed, tamper-evident assessment record. TITAN does all of that — in your environment, offline if you need it.

You were told the assessor piece is hard. It is — it's the part most tools skip and leave to a consultant. TITAN builds it in. Here is exactly what it does, and where the one legal line sits that no software on earth can cross (not us, not the incumbents).

Scan → score → review → correct → sign.

Maturity scoring

Five levels, not pass/fail

Every control is scored on the same five-level maturity model a HITRUST r2 assessment uses — Policy, Procedure, Implemented, Measured, Managed. A control isn't “done” because a box is checked; it's scored on how deeply it actually operates. Pass threshold is “Implemented” or higher, exactly as an assessor grades it.

PRISMA 0–5 maturity · weighted rollup · domain + overall score
Evidence review

Every artifact has a review state

Auto-collected, submitted, accepted, rejected, or needs-more — each control's evidence carries a review status, a reviewer, and a timestamp. Technical evidence TITAN pulls from the environment starts as auto-collected; human-process evidence is submitted by an owner and accepted or bounced back.

Reviewer · state · timestamp · audit trail
Corrective action plans

Every gap becomes a CAP

Any control below the pass level generates a Corrective Action Plan: the finding, current vs. target maturity, the exact remediation, the owner, a severity-based due date, and whether TITAN can auto-fix it. This is the deliverable an assessor hands back — TITAN generates it automatically.

Owner · due date · remediation · auto-fixable flag
Signed record

Tamper-evident assessment

The finished assessment is a signed object: an assessment ID, an overall maturity score, per-domain scores, the full control list, the CAP register, and a SHA-256 content signature. Change one byte and the signature no longer matches. An external assessor can review and attest against it; for TITAN-HSF, TITAN signs it directly.

Assessment ID · SHA-256 signature · reproducible

Where TITAN is the assessor — and where it can't be.

TITAN-HSF (our framework)HITRUST CSF
Scoping & maturity scoringTITANTITAN
Evidence collection & reviewTITANTITAN
Corrective action plansTITANTITAN
Signed assessment recordTITANTITAN (readiness)
Validated assessmentTITAN — directlyAuthorized External Assessor firm
Certificate issued byTITAN attestationHITRUST, via that assessor

Why this is a strength, not a gap. HITRUST's own rules forbid any single party from both preparing a client and issuing that client's validated certificate — there's a mandatory 12-month independence separation. So no product can be the HITRUST assessor: not TITAN, not Vanta, not Drata. What TITAN does is everything up to that line — the months of scoping, evidence, scoring, and remediation — so the external assessor's job shrinks from months to days. And for the many healthcare companies that don't need HITRUST at all, TITAN-HSF is a fully validated assessment TITAN issues itself, with no external firm involved.

Assessed on your Azure, by your rules.

See a signed assessment of your environment.

Read-only deploy in your tenant. Maturity-scored, CAP-complete, tamper-evident — in minutes.