TrustCenter

The trust center checklist

Tick what exists today. The blanks are what a reviewer will ask for in a questionnaire.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Use this checklist to build or audit a trust centre. Each line names the thing a reviewer looks for and the artifact that proves it. Your progress is saved in your browser. The readiness score gives the same check as a scored result.

Assurance

0 of 0 done ·

Getting this section right

Evidence that passes. Documents with dates a reviewer can check against today: report periods, certificate expiry, test dates within the last year.

Typical timing. Days, if the documents exist. A bridge letter is an afternoon.

Common mistakes. An expired report period with no bridge letter; "SOC 2 certified"; publishing the full report openly.

In Canada. Canadian CPA firms issue SOC 2 reports accepted by US buyers. State the report is available under NDA rather than naming the firm unless you have permission.

Data and privacy

0 of 0 done ·

Getting this section right

Evidence that passes. Region names, vendor names and dates. "Hosted in Canada" alone does not pass.

Typical timing. One to two weeks, mostly confirming every vendor that touches personal data.

Common mistakes. Forgotten support desks, email and analytics tools; a list that disagrees with the DPA.

In Canada. PIPEDA keeps your customer accountable for what you process, Law 25 section 17 requires a transfer assessment outside Quebec, and Bill C-36 (introduced 15 June 2026, at second reading) would add a cross-border assessment duty.

Controls summary

0 of 0 done ·

Getting this section right

Evidence that passes. Statements a reviewer could check against your report. Each should match a control your auditor tested.

Typical timing. Two to three days to write from SOC 2 or ISO evidence.

Common mistakes. Marketing language; claims wider than the report; no dates.

In Canada. Background checks are subject to provincial privacy and human rights law. Describe what you do, not what a US template says.

Access and requests

0 of 0 done ·

Getting this section right

Evidence that passes. A log that answers "who has our report" in one lookup.

Typical timing. A week, mostly counsel reviewing the NDA once.

Common mistakes. Bespoke NDAs per request; one busy approver for everything.

In Canada. Have counsel confirm the click-through wording and the acceptance record for Canadian enforceability.

Operations

0 of 0 done ·

Getting this section right

Evidence that passes. A last-reviewed date on the page that is less than a quarter old.

Typical timing. An hour to set up; an hour a quarter to run.

Common mistakes. No owner after the SOC 2 project ends.

In Canada. PIPEDA requires breach records and reporting where there is a real risk of significant harm; your customers rely on your notice to meet it.

What to do next

Fill the gaps in order. Assurance and data first: they end the most questions.

Decide who runs it. See self-managed or managed.

Get quotes if you want help. The quote form reaches providers who set up or run trust centres.

Common questions

How many items does a trust centre need before launch?

The assurance and data sections matter most. A page with honest status, residency and subprocessors can launch, and the rest follows within weeks.