What is a trust center?
A trust center is a public web page where a company shares its security posture, compliance reports, policies, and subprocessors so prospective and current customers can vet it quickly, reducing back-and-forth during security review.
Definition
A trust center is a company-published page or portal that presents its security and compliance posture in one place, including certifications, policies, subprocessors, and often a way to request documents under NDA.
Background
When a buyer evaluates a vendor, its security team asks the same questions many vendors already answer: which reports do you hold, how is data encrypted, who are your subprocessors, how do you handle incidents. A trust center puts those answers in a durable public place so the buyer can self-serve, and gates sensitive documents (like a full SOC 2 report) behind a request or NDA.
Why it matters
Security review is often where deals wait. A good trust center shortens that review by answering common questions up front, which reduces the number of custom questionnaires a vendor has to complete and moves deals faster. It also signals maturity and transparency to buyers.
Step by step
- State which frameworks or reports you hold (or are working toward), accurately.
- Summarize core practices: encryption, access control, monitoring, incident response.
- List your subprocessors and where data is processed.
- Link your public policies and a security contact or vulnerability-disclosure path.
- Gate sensitive documents behind a request or NDA rather than posting them openly.
Examples
- A buyer reads a vendor's trust center, confirms it holds the reports they need, and skips sending a custom questionnaire.
- A trust center lists subprocessors and data residency, and offers the full audit report on request under NDA.
Common mistakes
- Claiming certifications or reports you do not actually hold, which is a serious trust and liability problem.
- Posting confidential audit reports publicly instead of gating them.
- Letting the page go stale so it no longer matches your real posture or subprocessor list.
FAQ
What should a trust center include?
At minimum: the reports or frameworks you hold, a summary of your security practices, your subprocessors and data residency, links to public policies, and a security or vulnerability-disclosure contact. Sensitive documents are usually available on request under NDA.
Is a trust center the same as a SOC 2 report?
No. A trust center is a public overview of your posture; a SOC 2 report is a specific auditor-issued report. A trust center often links to or offers the SOC 2 report on request, but it is not a substitute for one.
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free