Skip to content

Internal

This is the largest chapter in the TrustSource documentation. It covers everything you do between bringing data in (Inbound) and generating compliance documents (Outbound).

In this chapter

Section What it covers Key roles
Products CRA-classified products with contacts, photos, documents, misuse cases and solution links. developer + (license: products)
Projects Create, configure and manage projects — the organisational containers for your modules. 12 settings tabs. manager, account_admin
Modules The unit of analysis — components, licenses, vulnerabilities, dependencies. 8 detail tabs, 18 settings tabs. developer, compliance_manager
Risks Risk register with financial metrics, portfolio views and task management. developer + (license: risks)
Approvals Formal release approvals with eight review tabs — the quality gate before shipping. compliance_manager
Releases Published releases with frozen SBOMs and post-release vulnerability monitoring. developer +
Reports Hub page linking to all report types (SBOM, SOUP, Notice, CSAF). compliance_manager +
Threat Models STRIDE and LINDDUN threat modelling with document store (OTM / OWASP Threat Dragon). developer + (license: threat)

[!TIP] The typical workflow is: create a projectadd modulesscanreview findingsapprovereleasegenerate documents. Follow the sections in order for a natural progression through that flow.