TrustCenter

A trust center before your first report

Buyers read a clear status far better than silence. A company without a report can still end many reviews at the first page.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

You do not need a SOC 2 report or an ISO 27001 certificate to publish a useful trust centre. Publish a factual controls summary, your subprocessors and data locations, your privacy policy and a vulnerability contact, and state your certification status with dates: for example, "SOC 2 Type 1 readiness under way, examination planned for Q1 2027". Many reviewers accept that for a first deal, especially from a smaller supplier, and it answers the questions they would otherwise send in a spreadsheet.

What can we publish without a report?

  • Controls summary. Access control, MFA, encryption, logging, backups, patching, secure development. Factual and dated.
  • Subprocessors and data locations. Canadian buyers ask these first, and they have nothing to do with a report.
  • Your cloud provider's reports. Reference AWS, Azure or Google Cloud compliance documentation for the infrastructure layer they run.
  • Penetration test letter. An independent test is strong evidence before an audit exists.
  • A dated status. What you are pursuing and when. Only publish a date you intend to keep.

How should we describe our status?

Name the framework, the stage and the date. "In progress" with no date reads as a hope. "SOC 2 Type 2 observation period began 1 September 2026; report expected Q2 2027" reads as a plan. Never write "SOC 2 compliant" before a report exists, and never write "SOC 2 certified" at all, because SOC 2 is an attestation, not a certification. The SOC 2 certification page on GetSOC2 explains the vocabulary.

Will enterprise buyers accept it?

Some will, some will not. Mid-market buyers and first deals often proceed on a clear controls summary, a penetration test letter and a dated plan, sometimes with a contract clause requiring the report by a date. Large banks and regulated buyers usually require the report. A trust centre helps in both cases because it shows you are organized, which is what a reviewer is really judging.

Common questions

Is it misleading to have a trust centre without a SOC 2 report?

Not if it says so plainly. It is misleading to imply a report or certification you do not hold. A dated, accurate status is what reviewers expect from a company at your stage.

Should we wait until the report is issued?

No. Reviews are happening now, and the public content, subprocessors, data locations and controls, is the same before and after. Add the report to the gated library when it arrives.

Launch a trust centre before your report

Providers can build it from your controls and add the report later.

Get matched