Vendor risk

What is a trust center?

A trust center is a public web page where a company shares its security posture, compliance reports, policies, and subprocessors so prospective and current customers can vet it quickly, reducing back-and-forth during security review.

Definition

A trust center is a company-published page or portal that presents its security and compliance posture in one place, including certifications, policies, subprocessors, and often a way to request documents under NDA.

Background

When a buyer evaluates a vendor, its security team asks the same questions many vendors already answer: which reports do you hold, how is data encrypted, who are your subprocessors, how do you handle incidents. A trust center puts those answers in a durable public place so the buyer can self-serve, and gates sensitive documents (like a full SOC 2 report) behind a request or NDA.

Why it matters

Security review is often where deals wait. A good trust center shortens that review by answering common questions up front, which reduces the number of custom questionnaires a vendor has to complete and moves deals faster. It also signals maturity and transparency to buyers.

Step by step

  1. State which frameworks or reports you hold (or are working toward), accurately.
  2. Summarize core practices: encryption, access control, monitoring, incident response.
  3. List your subprocessors and where data is processed.
  4. Link your public policies and a security contact or vulnerability-disclosure path.
  5. Gate sensitive documents behind a request or NDA rather than posting them openly.

Examples

  • A buyer reads a vendor's trust center, confirms it holds the reports they need, and skips sending a custom questionnaire.
  • A trust center lists subprocessors and data residency, and offers the full audit report on request under NDA.

Common mistakes

  • Claiming certifications or reports you do not actually hold, which is a serious trust and liability problem.
  • Posting confidential audit reports publicly instead of gating them.
  • Letting the page go stale so it no longer matches your real posture or subprocessor list.

FAQ

What should a trust center include?

At minimum: the reports or frameworks you hold, a summary of your security practices, your subprocessors and data residency, links to public policies, and a security or vulnerability-disclosure contact. Sensitive documents are usually available on request under NDA.

Is a trust center the same as a SOC 2 report?

No. A trust center is a public overview of your posture; a SOC 2 report is a specific auditor-issued report. A trust center often links to or offers the SOC 2 report on request, but it is not a substitute for one.

Related

Trust center in Keel → What is a security questionnaire? → What is a subprocessor? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free