Managed trust centers in Canada
Buying trust centre software is easy. Keeping someone on the inbound questions, the NDA requests and the stale policies is the part that slips. A managed trust centre is that job, handed to someone who does it every day.
A managed trust centre is a trust centre that a provider hosts and operates on your behalf. The provider publishes and maintains your security page, answers inbound security questions from buyers, handles requests for gated documents under NDA according to rules you set, keeps reports, policies and subprocessors current, and sends you a monthly report of who viewed and requested what. You approve the content and handle only what genuinely needs you.
It is priced per organization, because the work depends on how many reviews you receive and how much content exists when you start. No honest provider can quote it before asking both.
Hosted On your subdomain, run by the provider
Answered Inbound security questions and document requests
Reported Access log and a monthly summary
What does a managed trust centre include?
The core of a managed service is six pieces of ongoing work on top of the setup. Security questionnaires, the long custom spreadsheets some buyers send, are usually an add-on because their size varies from twenty questions to several hundred. Everything below is the standard scope TrazTech works to, and it is a fair checklist to put to any provider.
| Part | What happens | What you do |
|---|---|---|
| Hosting and setup | Page built on your subdomain, content drafted from your existing reports and policies, document library loaded, NDA flow configured | Review and approve the content once |
| Inbound security questions | Questions arriving through the page or forwarded by sales are answered from approved content, within an agreed response time | Answer only the questions the approved content does not cover |
| Document requests under NDA | Requests checked against your rules (existing customer, named prospect, open opportunity), NDA collected, document released, record kept | Set the rules; approve exceptions |
| Keeping it current | Report periods, certificate dates, policy versions and the subprocessor list checked on a calendar and updated, with a dated change log | Tell the provider when something changes internally |
| Access log and monthly report | Who viewed, who requested, what was released, which questions came in and how long answers took | Read it, and pass hot accounts to sales |
| Named contact and response times | One person who knows your environment, with a first-response target for questions (one business day on TrazTech's managed tier) | Nothing, beyond knowing who to call |
| Security questionnaires (add-on) | Full questionnaires drafted from the approved answer library, sent to you for sign-off | Sign off before submission |
The answers are always yours
A provider drafts and sends answers from content you approved. It never invents a control you do not have, and anything new goes to you before a buyer sees it. A managed service that answers questionnaires with statements nobody at the company checked is creating contractual risk, because those answers often end up attached to the contract.
When does a managed trust centre pay for itself?
It pays when the hours your own team spends on security reviews cost more than the service, or when slow answers are costing deals. The usual signs are a CTO answering questionnaires at night, NDA requests waiting days for an approver, and a trust centre that still lists last year's report. The security review cost calculator puts your current hours into Canadian dollars.
- Count a quarter of reviews. Questionnaires, document requests and ad hoc security emails, all of them.
- Estimate hours per review. Include the time to find the right answer, not just to type it.
- Price those hours at a loaded rate. For a senior engineer or security lead in Canada, $100 to $150 CAD an hour is a reasonable planning figure.
- Add what slowness costs. One deal slipping a quarter can outweigh a year of review hours.
- Compare with a quote. A provider can quote once it knows your volume and what already exists.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Is a managed trust centre the same as a trust centre platform?
No. A platform is software you log into and operate. A managed trust centre is the operation itself, delivered on a platform or on a page the provider hosts. Some companies pay for both: a compliance platform with a trust centre feature, and a provider to run it. Others use the provider's hosting and skip a separate platform licence. The platform comparison sets out what each vendor sells, and the cost page shows how the two add up.
Who is a managed trust centre for?
- Companies with a report but no security team. The SOC 2 is done, the auditor has gone, and the person who ran the project has a day job again.
- Sales-led companies with lumpy review volume. Six reviews in the week before quarter end, then none for a month.
- Companies selling into regulated Canadian buyers. Banks under OSFI B-10, health organizations under PHIPA, and public bodies ask detailed residency and subprocessor questions every year.
- Companies whose CTO is the bottleneck. If every answer waits for one person, the fix is not better software.
It suits a company with a full-time security or GRC hire less well. That person can run a platform directly, and a provider adds a layer. The honest answer for many companies is self-managed now, managed when volume or deals demand it.
How does onboarding work?
- Inventory. Reports, certificates, policies, subprocessors, data locations and past questionnaire answers are collected in one place.
- Draft. The public page and a controls summary are written from that material. Gaps are listed, not papered over.
- Rules. You decide who gets gated documents automatically, who needs approval, and which NDA applies.
- Launch. The page goes live on your subdomain, sales gets the link, and the request inbox moves to the provider.
- Run. Questions answered, requests handled, a monthly report, and a review of content every quarter.
With a current report and policies, launch typically takes two to four weeks. Without a report, the page can still go live with an honest status. See a trust centre before your first report.
What a Canadian provider should handle
A provider running a Canadian company's trust centre should know which privacy statute applies to you and write the page accordingly: PIPEDA accountability for processors, Law 25 governance publishing and transfer assessments for Quebec personal information, PHIPA for Ontario health information, and the cross-border assessment Bill C-36 would add if passed. It should state data residency plainly, including which cloud region holds production data and backups. The data residency and subprocessor pages cover the detail.
Who offers it
TrazTech Inc., which operates this site, offers two tiers, described on TrazTech's trust centre setup page. Both use the same trust centre, hosted by TrazTech.
| What happens | Self-managed | Managed |
|---|---|---|
| Trust centre setup and hosting | TrazTech | TrazTech |
| Answering inbound security questions | Your team | TrazTech, one business day first-response target |
| SOC 2 report and policy requests under NDA | Your team | TrazTech, released on your approval |
| Record of who received which document, and when | Your team | TrazTech |
| Keeping reports, letters, policies and dates current | Your team | TrazTech |
| Subprocessor change notices to buyers | Your team | TrazTech |
| Monthly activity and buyer report | Not included | Included |
| Full security questionnaires | Separate service | Optional add-on, quoted |
| Price | Free for TrazTech clients, monthly hosting otherwise | Quoted per organization |
Other Canadian providers are in the directory, and the questions to ask a provider apply to all of them, including us.
Trust centres by city
The work is remote, but buyers and privacy law differ by province. Pages for Toronto, Montreal, Vancouver, Calgary, Ottawa, Edmonton, Quebec City, Winnipeg, Hamilton, Kitchener-Waterloo, London, Halifax, Victoria, Windsor, Oshawa, Saskatoon, Regina, St. John's, Barrie, Kelowna cover what a company in each city should publish.
Common questions
How much does a managed trust centre cost?
It is quoted per organization, based on how many security reviews and document requests you receive, whether questionnaires are included, and how much content exists at the start. Ask for a quote with your last quarter's review count to hand, and compare it with what those reviews cost you in hours today.
Does a managed trust centre answer full security questionnaires?
Usually as an add-on, because questionnaires vary from twenty questions to several hundred. The provider drafts answers from your approved answer library and sends them to you for sign-off before anything reaches the buyer.
Who owns the content if we stop the service?
You should. Ask for a written commitment that the page content, the answer library, the access log and the document library are exported to you on termination, in a format you can load somewhere else.
Can the provider sign NDAs for us?
The provider collects the NDA on your behalf using your template, so the agreement is between your company and the requester. It should never be the provider's own NDA, because that would put your documents under someone else's contract.
Is our data safe with a provider hosting the trust centre?
Treat the provider as a subprocessor: ask where it hosts, who can access gated documents, how access is logged, and put it on your own subprocessor list. A provider that cannot answer those questions about itself should not answer them for you.
Get a managed trust centre quoted
Tell us your review volume and what you already have. Quotes come back priced on your organization, not a generic tier.
Get matched