Trust centers for Canadian companies
A trust centre is a page that answers the security questions buyers ask before they sign, and a process for handling the ones it cannot answer. The page is easy. The process is where companies fall behind.
Compare the firms yourself, or describe the job once and we will send it to the ones that do this work in Canada. Both are free.
A trust centre is a public page, usually at trust.yourcompany.com, that answers a buyer's security questions before they send a questionnaire. It lists your certifications and reports, your subprocessors, where data is stored, how you handle incidents, and it lets a reviewer request gated documents such as a SOC 2 report under a click-through NDA. For a Canadian B2B software company answering more than a handful of security reviews a quarter, it is the cheapest way to get days back.
There are two ways to run one. Self-managed means you set it up, on a platform or a page you host, and your own team answers what comes in. Managed means someone else hosts it and does the work: answers inbound security questions, approves document requests, keeps the content current, and reports what buyers looked at. Which one fits depends less on the software than on who in your company has the hours.
1 page Replaces the first round of most security reviews
2 models Self-managed, or managed and hosted for you
CAD Every price on this site, with the reason for the range
This site is operated by TrazTech Inc., a security and compliance practice in Toronto that sets up and runs trust centres. That is disclosed wherever it comes up, and the guidance here holds whether or not you ever talk to us.
Start here
| Your question | Read this |
|---|---|
| What is a trust centre, and do we need one? | What a trust centre is |
| What does it cost in Canadian dollars? | Trust centre costs in Canada |
| Can someone else run it for us? | Managed trust centres |
| Should we run it ourselves or hand it off? | Self-managed or managed |
| Which platform? | Trust centre platforms compared |
| What goes on it, and what stays behind an NDA? | What to publish |
| We have no SOC 2 report yet. Is there any point? | A trust centre before your first report |
| We drown in questionnaires | Handling security questionnaires |
What a trust centre does that a PDF does not
Most companies start by emailing their SOC 2 report to whoever asks and pasting the same answers into a new spreadsheet each time. That works for three reviews a year. It breaks at three a month. A trust centre changes three things.
- The first answer is self-serve
- A reviewer reads your controls summary, your subprocessor list and your data residency statement before they write a questionnaire. Many reviews end there, or the questionnaire that follows is shorter.
- Gated documents are logged
- Your SOC 2 report is a restricted-use document. A request flow with an NDA records who asked, who approved it and when, which is the record a customer's auditor, and your own, will ask for.
- One source of truth
- Sales, security and support point to the same page. When a policy changes, it changes once.
What a trust centre does not do: it does not answer a 300-line custom questionnaire on its own, and it does not replace a report. It makes both cheaper to deal with. The detail is on trust centre versus a security page.
The managed option
The software is the small part. The job is answering what the page cannot: the custom question from a bank's third-party risk team, the NDA request at 6 pm on a Friday before a Monday signature, the policy that went out of date in March. A managed trust centre puts that job with someone whose work it is.
| Work | Self-managed | Managed |
|---|---|---|
| Set up the page, the domain and the document library | Done for you or by you | Done for you, and hosted |
| Answer inbound security questions | Your team | Handled, escalating only what needs you |
| Approve NDA document requests | Your team | Handled, to rules you set |
| Keep policies, reports and subprocessors current | Your team | Handled, with a dated change log |
| Access log and a monthly report of who looked at what | If your platform has it | Included |
| Named contact and response times | Not applicable | Included |
| Full security questionnaires | Your team | Optional add-on |
TrazTech's own version hosts both tiers: self-managed is free for TrazTech clients, with a monthly hosting fee otherwise, and managed adds a one business day first-response target on security questions. Managed trust centres are quoted per organization, because the work depends on how many reviews you get and how much content already exists. The self-managed or managed tool gives you an answer in six questions, and the security review cost calculator puts a Canadian dollar figure on what the job costs you today.
What is different for a Canadian company
American trust centre guides skip the three questions Canadian buyers ask most. Where is the data stored, and does it leave Canada? Who are your subprocessors, and did you assess them? What do you publish under your privacy law? Under PIPEDA you remain accountable for personal information a processor handles for you. Quebec's Law 25 requires a privacy impact assessment before personal information leaves the province and requires you to publish your governance policies on your website. Bill C-36, introduced on 15 June 2026 and at second reading, would add an explicit duty to assess and mitigate risk before transferring personal information outside Canada.
A trust centre is the natural place for those answers. The pages on data residency, subprocessor lists, Law 25 and Bill C-36 set out what to publish.
Free tools
Each renders its full answer on screen. The readiness score says what you can publish today, the publish or gate checker sorts your documents, and the questionnaire volume estimator projects the review load your pipeline will bring. All of them are on the tools page.
Common questions
What is a trust centre?
A trust centre is a web page where a company publishes its security and privacy posture for customers: certifications, reports, policies, subprocessors and data locations, with gated documents available on request under an NDA. It exists to answer security reviews before they turn into questionnaires.
Do we need a SOC 2 report before we have a trust centre?
No. A trust centre with honest controls, your subprocessors, your data locations and a dated plan for your first report shortens reviews on its own. Buyers read a clear "in progress" far better than silence.
What does a managed trust centre include?
Hosting, answering inbound security questions, handling document requests under NDA with approvals, keeping documents current, an access log with a monthly report, a named contact and agreed response times. Full questionnaires can be added. It is quoted per organization.
How much does a trust centre cost in Canada?
A basic self-hosted page costs little beyond the time to write it. A platform ranges from included in a compliance subscription you already pay for to a separate five-figure CAD annual contract. A managed service is quoted on your review volume. The cost page breaks it down.
Get quotes for setting up or running a trust centre
Tell us how many reviews you handle and what you have today. We will put it in front of providers who do this work in Canada.
Get matched