Keeping a trust center current
A stale trust centre is worse than none. Put its upkeep on a calendar tied to the events that change it.
Keep a trust centre current with two kinds of upkeep: event-driven updates, made the day something changes (a new report, a renewed certificate, a new subprocessor, a policy revision, an architecture change), and a quarterly review of the whole page against reality. Give one person ownership. Put the date of the last review on the page, so reviewers can see it is maintained.
What triggers an immediate update?
| Event | Update |
|---|---|
| SOC 2 report issued | Replace the report, update the period, retire the old one |
| Report period ends | Publish a bridge letter |
| ISO certificate renewed or surveillance audit passed | Update dates and certificate |
| New subprocessor | Give notice per your DPA, then add it |
| Policy revised | Update version and review date |
| New region or hosting change | Update the residency statement |
| Penetration test completed | Replace the letter |
What does the quarterly review cover?
0 of 0 done ยท
Who should own it?
Whoever owns security reviews, with a backup. If nobody has the time, that is the strongest sign a managed trust centre fits, because keeping content current is part of the service.
A year of upkeep, month by month
| When | Task |
|---|---|
| January | Report period ended 31 December: publish a bridge letter; quarterly review |
| March or April | New report issued: replace the report, update the period, retire the old one |
| April | Quarterly review; refresh the bridge letter if the report is late |
| July | Quarterly review; check policy review dates |
| Annually | New penetration test letter; subprocessor list reconciled with vendor contracts |
| October | Quarterly review; plan next year's report timing |
Where does drift come from?
Almost always from changes nobody told the owner about: a new vendor bought on a credit card, a feature that sends data to a new AI provider, a region added for a customer. Ask engineering and finance to copy the trust centre owner on new vendors and infrastructure changes. That one habit prevents most stale pages.
Common questions
How often should a trust centre be reviewed?
Quarterly in full, plus immediate updates when a report, certificate, subprocessor or policy changes.
Should the page show a last-updated date?
Yes. Reviewers look for it first, and it keeps the owner honest.
Have it kept current for you
Upkeep on a calendar, with a change log, in a managed service.
Get matched