Trust center provider directory
What a listing here means, how to compare providers, and how to get quotes from the ones that fit.
Filtering happens in your browser. Nothing is sent anywhere and the order never changes.
9 firms listed on TrustCenter.
Nothing matches those filters. to see every firm again.
Our offerings
TrazTech Inc. VerifiedOperates this site
The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.
Everyone else
Listed from public information and not yet claimed by the firm, so the details here are ours rather than theirs. If this is your firm, claim it and it becomes yours to edit.
ABM Integrated Solutions Unclaimed
IT firm whose compliance practice prepares clients for SOC 2 and ISO 27001 certification using a compliance automation platform, and does not issue certificates.
Canadian Cyber Unclaimed
Governance, risk and compliance consultancy that guides clients through ISO 27001 scoping, gap analysis, policy development and implementation ahead of an external certification audit, and does not issue certificates.
Cognisys Unclaimed
UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.
GAM Tech Unclaimed
Canadian managed IT and cybersecurity firm with offices from Vancouver to Montreal that completes and reviews customer security questionnaires alongside the client and maintains evidence packs.
GreenHat Security Unclaimed
Firm selling fractional and virtual CISO services positioned as security leadership that fits the company stage, with SOC 2 readiness work.
SecurityPal Unclaimed
Security questionnaire and trust center service that offers software, analyst-reviewed and fully managed tiers, with its analyst team based in Kathmandu.
Truvo Cyber Unclaimed
Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.
Workstreet Unclaimed
Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.
Browse a shorter list
The whole directory is above. These are the same firms cut down to one service or one province, which is usually the faster way in.
- Compliance advisory firms in Canada, 7 firms
- ISO 27001 firms in Canada, 5 firms
- ISO 42001 firms in Canada, 4 firms
- Penetration testing firms in Canada, 4 firms
- Security questionnaires firms in Canada, 9 firms
- SOC 2 readiness firms in Canada, 6 firms
- Trust center firms in Canada, 9 firms
- vCISO firms in Canada, 6 firms
How do I know I can trust one of these firms?
Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.
Is a listing here a recommendation?
No. Firms are listed from public information or added by the firm itself, and a Verified badge is a tier rather than an endorsement. Nothing on this page says a firm is the right one for you. Compare at least three.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
TrazTech Inc. (operates this site)
TrazTech Inc., a security and compliance practice in Toronto, operates this site and offers a self-managed trust centre setup and a managed trust centre, hosted and quoted per organization. See managed trust centres for the scope, or TrazTech's own trust centre setup page. When other providers are listed, the operator's listing is labelled and the order inside each tier is not for sale.
What kinds of provider are there?
| Type | What they sell | Compare them on |
|---|---|---|
| Platform vendors | Trust centre software you operate | Request workflows, export, currency; see the comparison |
| Setup consultants | A one-off build of your page and approval rules | What they hand over: content, library, rules |
| Managed providers | Hosting plus running it: questions, requests, upkeep | Response targets, approval rules, reporting, export |
| Compliance firms | Trust centre work alongside SOC 2 or ISO 27001 readiness | Whether the trust centre reads from the same evidence |
How should we compare providers?
Send each the same written questions. The twelve questions to ask a provider cover hosting, who approves answers, response times, NDAs, pricing basis and what you get back if you leave. Ask for a quote built on your last quarter's review count.
Are you a provider?
Firms that set up or run trust centres in Canada can list here. A free listing is available; how listings and tiers work is on that page.
Common questions
Why is only one provider listed?
Because this site is new, and listings are added only for real firms confirmed to do this work. The quote form reaches providers in the meantime.
Is the operator's listing ranked first because it pays?
The operator is listed first and labelled as the operator. Everyone else is ordered by tier, and the order inside a tier is not for sale.
Get quotes from trust centre providers
One scope, several providers, comparable answers.
Get matched