Trust center and security review glossary
The vocabulary buyers use in security reviews, defined in a sentence or two each.
These are the terms that come up when setting up a trust centre or answering a security review, defined briefly with a link to the page that covers each in depth.
Reports and certifications
- SOC 2
- An attestation report by a CPA firm on a service organization's controls, restricted in use. More.
- SOC 3
- A general-use summary of a SOC 2 examination that can be published openly.
- Type 1 and Type 2
- A Type 1 covers control design at a point in time; a Type 2 covers operation over a period.
- Bridge letter
- A supplier's own letter covering the time between a report period's end and today.
- Complementary user entity controls
- Controls a SOC 2 report assumes the customer operates, such as managing its own user access.
- ISO 27001
- A certifiable information security management standard; the 2022 version has 93 Annex A controls. More.
- Statement of Applicability
- The ISO 27001 document listing which Annex A controls apply and why.
- ISO 42001
- The AI management system standard.
Questionnaires
- SIG
- Shared Assessments' Standardized Information Gathering questionnaire, in Lite and Core versions. More.
- CAIQ
- The Cloud Security Alliance's questionnaire mapped to the Cloud Controls Matrix. More.
- CSA STAR
- The Cloud Security Alliance registry where providers publish CAIQ self-assessments and certifications.
- HECVAT
- A questionnaire used by higher education institutions to assess vendors.
- Answer library
- An approved set of reusable questionnaire answers. More.
Privacy and data
- Subprocessor
- A third party that processes customer personal data on a supplier's behalf. More.
- DPA
- A data processing agreement setting out how a supplier handles customer personal data.
- Data residency
- Where data is physically stored and processed. More.
- PIPEDA
- Canada's federal private-sector privacy law. More.
- Law 25
- Quebec's privacy reform law, with publishing and transfer assessment requirements. More.
- Bill C-36
- A federal bill, introduced 15 June 2026 and at second reading, that would replace Part 1 of PIPEDA. More.
- PHIPA
- Ontario's Personal Health Information Protection Act. More.
- OSFI B-10
- OSFI's guideline on third-party risk management for federally regulated financial institutions. More.
Trust centre terms
- Trust centre
- A page publishing a supplier's security posture, with gated documents on request. More.
- Gated document
- A document released only after an NDA and approval. More.
- Managed trust centre
- A trust centre hosted and run by a provider. More.
Common questions
What is the difference between a SOC 2 and a SOC 3?
A SOC 2 is a detailed, restricted-use report for customers and prospects. A SOC 3 is a short general-use version of the same examination that can be published openly.