How to set up a trust center
The page takes days. The decisions behind it, what you publish, what you gate and who approves, are what make it work. Do them in this order.
To set up a trust centre, gather the security material you already have, write a short controls summary from it, decide which documents are public and which sit behind an NDA, write down who approves requests, publish it on a subdomain, and put its upkeep on a calendar. A company with a current SOC 2 or ISO 27001 report can do this in two to four weeks. Without a report it takes about as long, and the page says honestly where you are.
Step 1: What do we need to gather first?
Everything a reviewer has asked you for in the past year, in one folder. The fastest source is your last three completed questionnaires: they show which questions buyers actually ask and what you answered.
0 of 0 done ยท
Step 2: How do we write the controls summary?
Write one or two factual sentences under each heading a questionnaire uses: access control, encryption, logging and monitoring, vulnerability management, secure development, backups and recovery, incident response, vendor management, people security and physical security. Each statement should be checkable. "All production access requires SSO with enforced multi-factor authentication, reviewed quarterly" is a statement. "We follow industry best practices" is not.
Never claim more than your evidence supports
Every sentence on a trust centre can end up quoted in a contract. If your SOC 2 report shows an exception on access reviews, do not publish "access is reviewed quarterly without exception". Publish what is true and what you changed.
Step 3: What should be public and what should be gated?
Publish anything that answers a reviewer without helping an attacker: certifications held, the controls summary, subprocessors, data locations, the privacy policy and a vulnerability disclosure contact. Gate anything detailed: the SOC 2 report, penetration test output, full policies and completed questionnaires. What to publish goes item by item, and the publish or gate checker sorts your own list.
Step 4: Who approves document requests?
Write three rules before launch and the request flow runs itself. Existing customers get gated documents after accepting the NDA. Prospects with an open opportunity in your CRM get them after the NDA and a sales owner's confirmation. Everyone else waits for a named approver. Document request workflows covers the edge cases, such as competitors and researchers.
Step 5: Where should it live?
Use a subdomain such as trust.yourcompany.com so reviewers recognise it as official. The page itself can be on your own site with a request form, inside a compliance platform you already pay for, on a standalone trust platform, or hosted by a managed provider. The platform comparison and the cost page help you choose.
Step 6: How do we launch it?
Link it from your website footer, your sales email signature and every proposal. Send sales a one-line answer to "can you send your SOC 2" that points to the page. Tell your three most active prospects directly. Reviewers who find it on their own are the goal, but the first month depends on your team using it.
Step 7: How do we keep it current?
Review the whole page quarterly, and update immediately when a report period ends, a certificate renews, a policy changes version or a subprocessor is added. A stale page costs more trust than no page. Keeping it current sets out the calendar.
Common questions
How long does it take to set up a trust centre?
Two to four weeks for most companies with a current report and policies. The page is quick; writing the controls summary, confirming subprocessors and agreeing approval rules take the time.
Who should own the trust centre internally?
Whoever owns security reviews today, with sales and legal as reviewers of the content. If nobody owns reviews, fix that first or use a managed trust centre.
Can we launch before our SOC 2 report is issued?
Yes. Publish your controls, subprocessors and data locations with a dated status for the report. See a trust centre before your first report.
Have it set up for you
Providers can take your folder and hand back a live trust centre.
Get matched