What is a trust center?
A trust centre is the page a buyer's security reviewer reads before deciding how hard to question you. Done well, it ends a lot of reviews at the first step.
A trust centre is a web page, usually on a subdomain like trust.yourcompany.com, where a company publishes its security, privacy and compliance posture for customers and prospects. It shows which reports and certifications you hold, lists your subprocessors and data locations, summarises your controls, and lets a reviewer request gated documents such as a SOC 2 report under a click-through NDA. Its job is to answer the first round of a security review without a meeting or a questionnaire.
The glossary defines the terms you will meet. The term comes from the vendors that sell trust centre software, which is why most of what you will read about it is a product page. The idea is older and simpler: put the answers where the reviewer will look, and make the documents that need an NDA easy to get legitimately.
Public Controls summary, subprocessors, data locations, policies overview
Gated SOC 2 report, penetration test summary, detailed policies
Logged Who asked for what, who approved it, and when
What is on a trust centre?
A trust centre carries two layers. The public layer answers the questions every reviewer asks first: certifications held, where customer data is stored, which subprocessors touch it, how access is controlled, how incidents are handled. The gated layer holds restricted documents, released after an NDA and an approval. What to publish goes through both, item by item.
| Item | Layer | Why a reviewer wants it |
|---|---|---|
| Certifications and reports held, with dates | Public | The first filter in any vendor review |
| Controls summary by area (access, encryption, logging, backups) | Public | Answers the first twenty questions of most questionnaires |
| Subprocessor list with purpose and location | Public | Required reading for privacy and procurement teams |
| Data residency statement | Public | The first question Canadian public sector, finance and health buyers ask |
| Privacy policy, and Law 25 governance policies where they apply | Public | A legal requirement in Quebec, and expected everywhere |
| Incident and vulnerability disclosure contact | Public | Shows someone owns the problem |
| SOC 2 report or ISO 27001 certificate and Statement of Applicability | Gated | The SOC 2 report is restricted use by design |
| Penetration test executive summary or letter of attestation | Gated | Proves testing without handing out findings |
| Detailed policies (incident response, business continuity) | Gated | Useful to a reviewer, useful to an attacker too |
| Completed standard questionnaires (SIG, CAIQ) | Gated | Pre-answers the long form a reviewer was about to send |
Who needs a trust centre?
A company needs one when security reviews start costing real hours or real deals. For most Canadian B2B software companies that is somewhere between a handful of enterprise reviews a quarter and the first time a deal stalls because nobody answered a question for two weeks. Company size matters less than who you sell to.
- You sell to enterprises, banks, insurers, health organizations or government. Their reviews are formal and repeat every year. A trust centre pays for itself here first.
- You answer the same questions repeatedly. If your team has pasted the same encryption answer into five spreadsheets this year, the answer belongs on a page.
- You email your SOC 2 report as a PDF. A restricted-use report sent without an NDA or a log is a governance gap your own auditor may ask about.
- You sell to small businesses on a card. You probably do not need one yet. A short security page is enough.
Under about twenty staff, with no report and a few reviews a year, a security page does most of the job. The readiness score tells you which side of that line you are on.
What does a trust centre replace?
It replaces the email thread. The pattern before a trust centre is familiar: a prospect asks for your SOC 2 report, someone digs it out of a shared drive, sends it, forgets to record it, and the same prospect's procurement team asks again three weeks later. It also replaces the first questionnaire for many reviewers, who read the page and send a shorter, targeted list instead.
It does not replace the report itself, the long custom questionnaire a large bank sends regardless, or the person who has to answer what the page cannot. Handling questionnaires covers the second, and managed trust centres cover the third.
Does a trust centre need special software?
No. A trust centre can be a well-built page on your own site with a form for document requests. Platforms add three things worth paying for at volume: NDA e-signature built into the request, approval workflows with an access log, and analytics on which accounts viewed what. The platform comparison covers who sells what, and the cost page puts CAD ranges against each route.
A page without an owner goes stale
The most common failure is a trust centre that listed a subprocessor you dropped a year ago and a report period that has expired. A reviewer who spots one stale fact assumes the rest are stale too. Decide who owns updates before you publish anything. Keeping it current sets out the calendar.
Should we run it ourselves?
Run it yourselves if one person has a few hours a week and reviews are predictable. Hand it off if reviews arrive in bursts tied to deals, if the person answering is also your CTO, or if requests sit unanswered. A managed trust centre is hosted and run for you: inbound questions answered, NDA requests handled, content kept current, and a monthly report. Self-managed or managed sets out the decision.
What changes for a Canadian company?
Canadian buyers ask where data is stored and who processes it before they ask anything else. Under PIPEDA you stay accountable for personal information a processor handles for you. Quebec's Law 25 requires publishing governance policies on your website and a privacy impact assessment before personal information leaves Quebec. A trust centre is where those answers live, and the data residency and Law 25 pages set out the wording.
Common questions
Is a trust centre the same as a security page?
No. A security page is a static description of your practices. A trust centre adds gated documents, an NDA request flow, access logging and usually a subprocessor list kept current. A security page is a good first step and many small companies need nothing more yet.
Can we publish our SOC 2 report openly on a trust centre?
You should not. A SOC 2 report is intended for customers and prospects with a need to know, which is why it is gated behind an NDA. If you want a public document, a SOC 3 report is the general-use version, and it costs extra from your auditor.
How long does it take to set up a trust centre?
The page takes days, not months, if the content exists. What takes time is writing the controls summary, confirming the subprocessor list and deciding what is gated. Most companies with a current report can launch within two to four weeks.
Do buyers actually read trust centres?
Security reviewers do, because it is the fastest way to decide how much more to ask. Procurement staff often start there before sending a questionnaire. A platform's analytics can show you which accounts viewed which pages, which is how you find out for your own buyers.
Get a trust centre set up, or run for you
Say what you have today and how many reviews you handle. We will match you with providers who do this in Canada.
Get matched