TrustCenter

Trust center and security review glossary

The vocabulary buyers use in security reviews, defined in a sentence or two each.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

These are the terms that come up when setting up a trust centre or answering a security review, defined briefly with a link to the page that covers each in depth.

Reports and certifications

SOC 2
An attestation report by a CPA firm on a service organization's controls, restricted in use. More.
SOC 3
A general-use summary of a SOC 2 examination that can be published openly.
Type 1 and Type 2
A Type 1 covers control design at a point in time; a Type 2 covers operation over a period.
Bridge letter
A supplier's own letter covering the time between a report period's end and today.
Complementary user entity controls
Controls a SOC 2 report assumes the customer operates, such as managing its own user access.
ISO 27001
A certifiable information security management standard; the 2022 version has 93 Annex A controls. More.
Statement of Applicability
The ISO 27001 document listing which Annex A controls apply and why.
ISO 42001
The AI management system standard.

Questionnaires

SIG
Shared Assessments' Standardized Information Gathering questionnaire, in Lite and Core versions. More.
CAIQ
The Cloud Security Alliance's questionnaire mapped to the Cloud Controls Matrix. More.
CSA STAR
The Cloud Security Alliance registry where providers publish CAIQ self-assessments and certifications.
HECVAT
A questionnaire used by higher education institutions to assess vendors.
Answer library
An approved set of reusable questionnaire answers. More.

Privacy and data

Subprocessor
A third party that processes customer personal data on a supplier's behalf. More.
DPA
A data processing agreement setting out how a supplier handles customer personal data.
Data residency
Where data is physically stored and processed. More.
PIPEDA
Canada's federal private-sector privacy law. More.
Law 25
Quebec's privacy reform law, with publishing and transfer assessment requirements. More.
Bill C-36
A federal bill, introduced 15 June 2026 and at second reading, that would replace Part 1 of PIPEDA. More.
PHIPA
Ontario's Personal Health Information Protection Act. More.
OSFI B-10
OSFI's guideline on third-party risk management for federally regulated financial institutions. More.

Trust centre terms

Trust centre
A page publishing a supplier's security posture, with gated documents on request. More.
Gated document
A document released only after an NDA and approval. More.
Managed trust centre
A trust centre hosted and run by a provider. More.

Common questions

What is the difference between a SOC 2 and a SOC 3?

A SOC 2 is a detailed, restricted-use report for customers and prospects. A SOC 3 is a short general-use version of the same examination that can be published openly.