Docs overview

Read the record before you send it.

A Trust Passport is a dated, sealed record of technical controls on listed Macs. It is not a certification, an audit opinion or a guarantee that a recipient will accept it.

Read it from scope to seal

  1. Check the Macs and the period

    Identify the listed devices, their owners and the chosen period. A score belongs beside the number of assessed devices.

  2. Read the controls and their dates

    Look at protection, hardening, application patch status and the recorded inventory. Distinguish a current observation from a period during which a control held.

  3. Review what is missing

    Keep unassessed devices and controls outside the record visible. Never turn a missing observation into a passing answer.

  4. Understand the seal

    The recipient checks that the page has not changed after sealing by comparing it with cybee’s sealed copy.

Coverage belongs beside the score

One cell = one sample Mac. Seven assessed. One unknown.

Illustrative coverage

7 of 8 Macsassessed in this example

The eighth Mac stays visible.

An unconnected Mac is not counted as assessed. The record cannot establish its protection or control state. A fleet average must not conceal that gap.

Check the assessed count beside the total, such as “7 of 8 Macs”, whenever you read a score or share a Passport.

Answer only what the record covers

What the record covers

  • Listed, assessed Macs
  • Encryption and endpoint protection with dates
  • Applications, screen lock, extensions and AI tools

What needs separate evidence

  • Google Workspace accounts and MFA in the account record
  • Backups, training completion and incident plan
  • Policies, code, suppliers and people

Connected Google Workspace accounts have a separate record. Training is included in the paid plan. Backup verification and the incident plan are in development. The device Passport is not a certification or an audit opinion.

Read the full scope definition

On a typical questionnaire the passport answers, with dates, the questions about your Macs: disk encryption on every listed Mac; endpoint protection that watches behaviour, and since when; the patch status of your applications; screen lock and password on wake; the browser extensions and AI tools installed. Connected Google Workspace accounts and their MFA settings have a separate account record. They are not part of this device Passport. Backups, training completion and the incident plan also need separate evidence. This record never answers for your policies, code, suppliers or people. It says so on the page.

For a client questionnaire, match each request to the corresponding device fact and date. The client decides whether the material meets their requirements. A technical record cannot replace evidence about organisational controls.

Security training includes completion tracking. Training completion is kept separately from the device and Workspace records. Security training

What verification proves

Verification checks the integrity of the sealed page against cybee’s sealed copy. It does not establish independence from cybee and does not prove that a device was impossible to compromise.

The verification instructions are not yet included in this guide. Request them from [email protected] before asking a recipient to verify a Passport.

Sharing and keeping access

The owner can revoke a Passport link. A sealed page remains unchanged. Link access is a separate matter: after a paid plan ends and its grace period expires, links to previously sent Passports stop working.

The grace period length needs confirmation. Check access expectations before relying on a link as a long term record. Evidence data can be requested as an export through the assistant.

Ask your assistant

Prepare the device record for this period. Show assessed coverage and anything outside the scope before I share it.

The next step is one command.

Protect your Mac, strengthen its settings and keep a dated record of the results.

For supported Macs. cybee is a Swiss company, independent, privacy first.

Chat · CLI · IDE · Terminal
curl -sSf https://get.cybee.dev | sh