TrustCenter

Self-managed or managed trust center

Both models use the same kind of page. The difference is who does the work behind it, and that is decided by your review volume and your people, not by the software.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Run a trust centre yourself if one person has a few predictable hours a week for it and reviews arrive at a steady pace. Choose managed if reviews come in bursts around deals, if the person answering is your CTO or head of engineering, or if document requests already wait days for an approver. A self-managed setup gives you the page and leaves the work with you. A managed trust centre is hosted for you and includes the work.

How do self-managed and managed compare?

Self-managed and managed trust centres side by side
QuestionSelf-managedManaged
Who builds the pageYou, or a provider as a one-off setupThe provider
Where it is hostedYour site or your platform accountThe provider hosts it on your subdomain
Who answers inbound security questionsYour teamThe provider, from approved content
Who handles NDA document requestsYour teamThe provider, to your rules
Who keeps it currentYour team, if someone remembersThe provider, on a calendar
ReportingWhatever your platform showsAccess log and monthly report
QuestionnairesYour teamOptional add-on
How it is pricedSetup plus your hours plus any platformQuoted per organization

When is self-managed the right choice?

Self-managed is right when you have a named owner with time, steady review volume and fast internal approvals. It is also right for most companies under about twenty staff, where reviews are few and the founder knows every answer. The risk is drift: the owner changes role, and the page quietly goes stale.

  • A security, compliance or GRC hire exists and owns reviews already.
  • Reviews arrive at one or two a week, not in clusters before quarter end.
  • Approvals for gated documents can happen the same day.
  • You already pay for a compliance platform with a trust feature and someone logs into it weekly.

When is managed the right choice?

Managed is right when the hours are real, the owner is overloaded, or slowness is already costing deals. It is also right after a SOC 2 project ends and the person who ran it goes back to a full-time job with nobody to catch the next hundred questions.

  • Your CTO or a senior engineer answers most security questions.
  • An NDA request has waited more than two business days in the last quarter.
  • The trust centre, or the security page, lists something that is no longer true.
  • You sell to banks, insurers, health organizations or government, whose reviews repeat every year.
  • Reviews cluster around deals and swamp whoever is on them.

The middle option

Many companies buy a one-off setup from a provider, run it themselves for a year, and move to managed when review volume climbs. That sequence works well if the setup includes an answer library and written approval rules, because those are what make a later hand-off quick.

How do we compare the cost of each?

Compare the managed quote with your own running cost, not with a platform licence. Take weekly hours spent on reviews, multiply by a loaded hourly rate and by fifty weeks. Three hours a week at $125 CAD is $18,750 a year before any software. Then add the cost of slow answers on deals in your pipeline. The security review cost calculator does the arithmetic, and the cost page sets out every line.

Can we switch later?

Yes, if you insist on two things from day one: content in a form you own, and an export of the answer library and access log. Moving from self-managed to managed is quick when approval rules are written down. Moving from managed back to self-managed is quick when the provider hands over the library and the document set, which should be in the contract. The questions to ask a provider include this one.

A quick way to decide

The six-question tool weighs volume, ownership, speed and buyer type and gives you an answer with the reasoning. If it says managed, the managed trust centre page lists the scope to ask for.

Common questions

Is a managed trust centre only for large companies?

No. It suits companies without a security team more than those with one, because a security hire can run a platform directly. A 40-person company with a SOC 2 report and a CTO answering every review is a typical managed customer.

Do we lose control of what is said about our security?

You should not. A provider answers from content you approved and sends anything new to you first. Ask for that rule in writing and for the monthly report to list every answer given.

Can we self-manage without a platform?

Yes. A page on your own site, a form that collects an NDA and sends documents after approval, and a spreadsheet log will do for low volume. The limits are logging and speed once requests climb.

Compare setup and managed quotes

One description of your review volume, quotes from providers that do either or both.

Get matched