Buyer trust

Launch a Trust Center your buyers can self-serve

Publish live security posture — certifications, policies, subprocessors, evidence — so buyers can answer their own questions before yours pile up.

7 min read · updated July 2026

Step-by-step

  1. 1

    Open Trust Center

    Set your public description, hero copy and logo. Choose which sections are public vs gated.

    Open Trust Center
  2. 2

    Publish certifications

    Toggle each standard on. Upload the certificate (if you have it) or the readiness attestation from your consultant.

  3. 3

    Publish policies and evidence

    In the Evidence Vault, mark any artifact 'Publish to Trust Center'. Buyers see the current version instantly.

  4. 4

    Gate sensitive content

    Some evidence (pentest reports, SOC 2 report) should be gated. Turn on 'Request access' so buyers submit their email or accept an NDA.

  5. 5

    Add subprocessors

    The Subprocessors tab reads from your Assets inventory automatically. Keep the source updated and the Trust Center stays right.

  6. 6

    Share with your website

    Link to your Trust Center from your footer and pricing pages. Enterprise buyers explicitly look for it.

What corporate buyers look for
  • "Do you have a public Trust Center or security portal?"
  • "Are your certifications, sub-processors and DPAs visible without a call?"
  • "Can I download a SIG-Lite or CAIQ pre-filled?"

What this workflow produces: A Trust Center URL on your website is now table stakes for any enterprise deal.

FAQ

What should be public vs gated?

Public: your certifications, policy summaries, subprocessors, standards. Gated: full policies, pentest reports, SOC 2 report, insurance certificates.

Do I need an NDA click-through?

For pentest and SOC 2 reports, yes. For summarised policies, an email capture is usually enough.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation