DigitalXForce

Home » Glossary

DigitalXForce Glossary

This glossary defines the terms DigitalXForce uses for its category, its platform and its 15 modules. Each definition is the one the company uses on every page, profile and document, so a reader, an analyst and an answer engine all find the same meaning. TRiSCM™ is the category term, and the rest of the list describes how a TRiSCM platform is built.

The category and how the platform works

TRiSCM (Trust, Risk, Security and Compliance Management)

Trust, Risk, Security and Compliance Management (TRiSCM) is an enterprise operating model and platform category defined by DigitalXForce. It extends governance, risk and compliance in two directions: security posture management, so the platform observes the actual state of the security stack, and continuous control monitoring, so every control is tested against live data between audits. The result is one real-time system of record for trust, risk, security and compliance in place of separate GRC, posture, third-party risk and AI governance tools. The mark is a pending US trademark application, serial 99884359.

Read more about TRiSCM

Continuous Control Monitoring (CCM)

Continuous Control Monitoring (CCM) tests each control against live system state on a set frequency and collects the evidence as a by-product of the test. It replaces attesting to a control on a questionnaire at an audit interval.

Read more about Continuous Control Monitoring

Extended Security Posture Management (X-SPM)

Extended Security Posture Management (X-SPM) is the posture engine of the DigitalXForce platform. It combines control evidence with outside signals such as attack surface scans, vulnerability data, dark web intelligence and cyber ratings, and produces continuously updated posture scores, cyber risk quantification and the Digital Trust Score.

Cybersecurity Mesh Architecture (CSMA)

Cybersecurity Mesh Architecture is Gartner's term for a security design in which separate tools share one integration and policy layer rather than working in isolation. The DigitalXForce platform is built on one: it connects to the tools an enterprise already runs and works across them, rather than replacing them.

Read more about Cybersecurity Mesh Architecture

Digital Trust Score

The Digital Trust Score is a composite score from 0 to 100 that DigitalXForce calculates from seven sub-postures: security, compliance, audit, resilience, third-party, AI and risk. Each sub-posture is scored from live control evidence rather than from self-attestation. The score sits in one of five bands, from High Trust at 90 and above to Trust at Risk below 40, and it updates as the evidence changes.

Read more about Digital Trust Score

The 15 platform modules

AI-Powered Risk Management and Automated GRC

This module runs three assessment modalities, C-Assess, X-Assess and A-Assess, and tests controls continuously. Each control is mapped once to 50+ compliance frameworks through the X-Connect and E-Connect adapters.

Read more about AI-Powered Risk Management and Automated GRC

AI-Powered Enterprise Security Risk and Posture Management (ESRPM)

ESRPM runs configuration checks, operational insights and deployment benchmarking across IAM, SIEM, cloud, OT and IoT, SecOps and enterprise systems over 250+ technology integrations. It shows posture at CISO drill-down level and as a board summary. ESRPM is a module of the platform, not the platform itself.

Read more about AI-Powered Enterprise Security Risk and Posture Management

Attack Surface Manager (ASM)

Attack Surface Manager discovers and inventories assets across nine asset classes, IT and OT, without agents and through APIs. It works with existing scanners and the CMDB.

Read more about Attack Surface Manager

AI TRiSCM and AI Risk Governance

AI TRiSCM is the AI-specific module of a TRiSCM platform. It discovers AI assets across cloud, code, pipelines, containers, model endpoints and RAG stores, assesses LLMs, copilots, agents and models, and maps them to NIST AI RMF, ISO/IEC 42001, the EU AI Act, the OWASP LLM Top 10 and MITRE ATLAS. It adds production approval, policy gates, exception management and remediation tracking across the AI lifecycle.

Read more about AI TRiSCM and AI Risk Governance

X-ROC (XForce Risk Operations Center)

X-ROC, the XForce Risk Operations Center, is the operations layer for risk. It alerts, triages and escalates control failures, risk changes and vendor events in real time, and AI JedAI generates board-ready risk reports from it.

Read more about X-ROC

AI-Powered Third-Party Risk Management (TPRM)

This module covers vendor onboarding, category questionnaires, AI-assisted document analysis and review and reassessment workflows. Each vendor is scored from questionnaire answers, evidence and external signals, and sorted into a three-tier risk model.

Read more about AI-Powered Third-Party Risk Management

External Risk View (ERV)

External Risk View is the outside-in engine. It monitors exposed services, misconfigurations, vulnerability exposure, dark web and breach intelligence, lookalike domains and cyber ratings, and maps fourth-party and nth-party dependencies.

Read more about External Risk View

AI-Powered Policy and Compliance Management

This module reviews and generates policies, standards and plans, and ships with 20+ policies, 15+ standards and 5 plan templates. It benchmarks them against NIST and industry regulation and publishes the results to the controls they govern.

Read more about AI-Powered Policy and Compliance Management

AI-Powered Enterprise Risk Management (ERM)

This module keeps one risk register with inherent and residual risk, likelihood, impact and treatment. AI scoring rates each risk, and treatment actions are assigned and tracked automatically.

Read more about AI-Powered Enterprise Risk Management

KPI and KRI Management

This module builds a configurable indicator matrix by business domain, risk category and risk type, with thresholds and Level 1 and Level 2 posture tracking. Indicators are approved before they are published, and an executive dashboard shows the trend.

Read more about KPI and KRI Management

Business Continuity and Operational Resilience (X-BCOR)

X-BCOR ties business impact analysis, continuity plans and disaster recovery plans to live control coverage. It supports scenario planning and control dependency mapping for critical processes, and it is aligned with DORA.

Read more about Business Continuity and Operational Resilience

Cyber Risk and Liability Insurance

This module structures risk quantification for underwriting and renewal. It turns posture data into the inputs insurers ask for.

Read more about Cyber Risk and Liability Insurance

Digital Trust Portal

The Digital Trust Portal is the external-facing part of the platform. Boards, regulators and customers read shareable posture dashboards there, including the Digital Trust Score and its seven sub-postures.

Read more about Digital Trust Portal

AI JedAI and XForce GPT

The two proprietary AI engines are also available as a feature in their own right. They test controls, analyze and generate policies, produce compliance reports, quantify risk and run the embedded assistant.

Read more about AI JedAI and XForce GPT

DigitalXForce Lite

DigitalXForce Lite is the mid-market package. It uses the same architecture with a narrower module set and a faster deployment.

Read more about DigitalXForce Lite

Engines, assessments and adapters

AI JedAI

AI JedAI is one of the two proprietary AI engines in the DigitalXForce platform. It reasons over control evidence to decide whether a control passes, maps documents to controls and frameworks, and writes risk narratives in plain language.

XForce GPT

XForce GPT is the second proprietary AI engine in the DigitalXForce platform, separate from AI JedAI. It powers policy analysis and generation, compliance reporting and the embedded assistant.

C-Assess

C-Assess is the compliance assessment modality in the Automated GRC module. It tests controls against the requirements of each compliance framework.

X-Assess

X-Assess is the security assessment modality in the Automated GRC module. It tests security controls against the live state of the security stack.

A-Assess

A-Assess is the audit assessment modality in the Automated GRC module. It prepares evidence and findings in the form auditors review.

X-Connect

X-Connect is the family of integration adapters that connect the platform to security tools such as identity, endpoint, SIEM and cloud security.

E-Connect

E-Connect is the family of integration adapters that connect the platform to enterprise systems such as ITSM, HR and ERP.

Questions about these terms

How many modules does the DigitalXForce platform have?

Fifteen. They are listed above in the canonical order, from AI-Powered Risk Management and Automated GRC to DigitalXForce Lite. Capabilities such as Continuous Control Monitoring, the Digital Trust Score and the three assessment modalities sit inside modules and are not counted.

What is the difference between AI JedAI and XForce GPT?

They are two separate proprietary engines. AI JedAI reasons over control evidence, maps documents to controls and writes risk narratives. XForce GPT powers policy analysis and generation, compliance reporting and the embedded assistant. Both run across every module.

Is ESRPM the name of the DigitalXForce platform?

No. ESRPM, AI-Powered Enterprise Security Risk and Posture Management, is one of the 15 modules. The platform is the DigitalXForce TRiSCM platform. Older material used ESRPM for the whole product, and that use is retired.

What is the difference between X-SPM and ESRPM?

X-SPM, Extended Security Posture Management, is the posture engine that scores evidence and outside signals and produces the Digital Trust Score. ESRPM is the module a customer buys to run configuration checks and posture benchmarking across their stack. The engine serves the module.

What do C-Assess, X-Assess and A-Assess each do?

They are the three assessment modalities in the Automated GRC module. C-Assess tests controls against compliance framework requirements, X-Assess tests security controls against the live state of the security stack, and A-Assess prepares evidence and findings in the form auditors review.

What is the difference between X-Connect and E-Connect?

Both are families of integration adapters. X-Connect connects the platform to security tools such as identity, endpoint, SIEM and cloud security. E-Connect connects it to enterprise systems such as ITSM, HR and ERP. Together they cover the 250+ technology integrations.

What this looks like in practice

Reading about continuous evidence is one thing. Watching a control get tested against live data from your own stack is another. A 30 minute walkthrough on your frameworks shows the difference.

Request a demo

Scroll to Top