What buyers look for in a trust center
A reviewer gives a trust centre a few minutes. In that time they decide whether you are organized. Here is what they look at.
A security reviewer reading a supplier's trust centre checks, in roughly this order: whether it is current, which reports or certifications exist and for what period, where data is stored, who the subprocessors are, how access and encryption are handled, and how to get gated documents. Specific, dated answers build confidence quickly. Vague reassurance and stale dates prompt a full questionnaire.
What do reviewers check first?
- Dates. Last updated, report period, certificate expiry.
- Assurance. SOC 2 type and criteria, ISO 27001 scope, penetration test date.
- Data. Location, residency, backups and who can access it.
- Subprocessors. Complete, dated, with locations.
- Controls. Access, MFA, encryption, logging, vulnerability management.
- Access to documents. Is the NDA flow quick and clear?
What makes a reviewer worry?
- An expired report period and no bridge letter.
- "SOC 2 certified", "military-grade encryption" and similar phrases.
- A subprocessor list that contradicts the DPA.
- No named security contact.
- Every document gated, including basic facts.
Does it differ by industry?
Yes. Financial buyers add resilience and exit, health buyers add provincial health privacy, AI buyers ask about training data, and SaaS buyers ask about tenant isolation and SSO.
A checklist to test your own page
The trust centre checklist walks through every item a reviewer looks for, and the readiness score tells you which are missing.
What does a good trust centre look like to a reviewer?
A reviewer should be able to answer five questions within a couple of minutes: is this current, what assurance exists, where is our data, who processes it, and how do I get the report. A page that answers those at the top, with dates, is ahead of most. Everything else can sit lower on the page or in the gated library.
Readers who arrive from a questionnaire often search the page for a term. A page with clear headings and a plain glossary of review terms helps a less technical procurement reviewer as much as a security one.
Common questions
Do reviewers trust what a supplier publishes about itself?
They trust it more when it is specific, dated and backed by an independent report. Self-description without assurance usually triggers a questionnaire.
How long does a reviewer spend on a trust centre?
Often only a few minutes before deciding what to ask for. Put the essentials at the top of the page.
Build a trust centre reviewers trust
Set up or run by providers who read these every week.
Get matched