# ColossalX Trust Engine: a trust score that explains itself.

> The ColossalX Trust Engine is an AI trust score that explains itself. It grades your AI estate A+ to F across five pillars, security, compliance, risk, resilience and AI governance, from live evidence. A pillar with no evidence carries no weight, a grade on thin evidence is marked provisional, and the page names the action that would raise it.

One grade across five pillars, built from live evidence, that says what pulls it down and what would raise it.

Canonical page: https://colossalx.tech/platform/trust-engine · Last reviewed: 6 Oct 2026

*Illustration:* Trust score · five pillars: C. Security measured; Compliance measured; Risk measured; Resilience not measured; AI governance measured. Provisional: resilience has no evidence yet

## The threat and the control

- **The threat:** The board is shown a security score nobody can explain, built partly on missing data.
- **The control:** ColossalX leaves out what it has no evidence for, marks the grade provisional, and says why.

## How it works: From a provisional grade to the action that raises it.

A grade that rests on thin evidence: marked provisional, explained pillar by pillar, and linked to the action that would supply what is missing.

### Workflow: a provisional grade, explained (illustrative)

1. **Pillars read.** Each pillar is scored from live evidence across the platform.
   Security: measured; Compliance: measured; Resilience: no evidence yet
2. **Marked provisional.** The grade rests on thin evidence, so it is labelled provisional.
   Grade C · provisional | Resilience is left out, not scored as zero.
3. **Explained.** It names the pillar costing most points and the distance to B.
   Pulling down: risk management; Next grade: B, a few points away
4. **Next action.** Each missing piece links to the page that would supply it.
   [Run a restore drill] [Register agents] | x, accounted for

## What you see: The score, explained pillar by pillar.

Each grade shows what pulls it down, the points the next grade needs, the evidence each pillar rests on and what is still missing.

1. **Five pillars, measured.** Security, compliance, risk, resilience and AI governance, scored from live evidence. The score is assembled from the gateway and agent security, the compliance position, the risk register, resilience tests and AI-governance coverage, and recalculated continuously. Each pillar shows its weight, its score and how much of the evidence it is designed to use was available.
2. **Provisional, not flattering.** A thin grade is provisional; a pillar without evidence weighs nothing. Anything with no evidence yet is left out rather than guessed, and listed with what would provide it. A grade must clear a boundary by a margin before it changes, so it does not flicker between two grades.
3. **Why, in plain words.** What pulls it down, and how far the next grade is. A per-pillar table shows weight, score, evidence coverage, points held and points lost, so the cost of each weak pillar is visible.
4. **The action that helps.** Each missing piece of evidence links to the page that supplies it. Typical actions: run a compliance assessment, run a restore drill, route traffic through the gateway, register agents or map AI-governance controls.

*Illustration:* An illustrative trust score, explained: five pillars with the evidence behind each, resilience shown as not measured rather than zero, a passing re-test that lifts the risk pillar and moves the grade from D to C (still provisional), and what would raise it next. Notes: 1. Provisional while evidence is thin 2. Not measured, never scored zero 3. What would raise the grade

## How we know

- A pillar with no evidence carries no weight, so a missing source never counts as zero.
- A grade on too little evidence is labelled provisional, not passed or failed.
- Only measured resilience tests count toward the resilience pillar.
- A grade must clear its boundary by a margin, so it does not flicker.

## Where the score is read next.

The score is read wherever a leader asks where the estate stands.

- **The overview.** The trust grade, its trend and the five pillar scores sit on the home overview.
- **Insights.** A falling score raises an insight, ranked with the measurements behind it.
- **Risk in money.** The risk pillar reads the same register that FAIR quantifies in money.
- **Compliance position.** The compliance pillar reads the same framework position, computed one way.

Where an x ends up: x, accounted for.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Mapped to NIST AI RMF: Read by the compliance pillar.
- Mapped to EU AI Act: Read by the compliance pillar.

## What it does not do

- There is no downloadable trust report yet; the export in the API returns data, not a document.
- Pillar weights and grade thresholds can be changed only through the API, not on screen.
- The score grades the AI estate as a whole; there is no per-asset trust score.
- The trust figure on an agent's page is a separate measure, not this grade.

*Illustration:* Pillar · no evidence yet: Pillar Resilience; Evidence None provided yet; Weight None until evidenced; Grade Provisional; Would supply it A restore drill. Left out, not guessed.

## Questions

### What is an AI trust score?

An AI trust score is a single grade for how safe and well governed an organisation's AI is. The ColossalX Trust Engine builds it from five pillars of live evidence, grades it A+ to F, and shows why: which pillars pull it down, which evidence is missing and what would raise it.

### What are the five pillars?

Security, from the gateway and agent security; compliance, from the framework position; risk, from the register; resilience, from measured chaos experiments and restore drills; and AI governance, from AI control coverage. Each pillar shows its weight, its score and how much of the evidence it is designed to use was available.

### Why is a grade sometimes marked provisional?

Because it rests on too little evidence to be trusted as a pass or a fail. A pillar with no evidence carries no weight, so a missing source is left out rather than counted as zero, and the grade says provisional until the evidence arrives. The page lists what would provide it.

### What raises the score?

Evidence and fixes. The page names the pillars costing most points and how far the next grade is, and links each missing piece of evidence to the action that supplies it, such as a restore drill, a compliance assessment, routing traffic through the gateway or registering agents. A proven fix to a red-team gap moves the resilience pillar.

### How does the score reach the board?

The grade, its trend and the pillar scores sit on the home overview, and a falling score raises an insight with the measurements behind it. Board reporting runs through the reports hub, where reports are branded, scheduled and signed off by a second person; a downloadable trust report itself is not available yet.

## Related

- [Risk quantification](https://colossalx.tech/platform/risk-quantification)
- [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- [Resilience](https://colossalx.tech/platform/resilience)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
