Security
What to publish in a trust center
A good trust center answers the security questionnaire before it is sent. A bad one is a logo wall. Here is what buyers actually look for, what to gate, and how to keep it live.
6 min read · Certifyi compliance team · Updated September 2026
Short answer. Publish your certifications and report types with dates, a summary of your controls by domain, your sub-processor list, your policies’ existence and review dates, and how to report a vulnerability. Gate the full SOC 2 report, penetration-test summary and detailed architecture behind a request with an NDA click-through. Keep it live by generating it from your compliance record, not by editing a web page.
What buyers look for first
- Which reports and certificates you hold, with the period covered and the auditor or certification body.
- Whether your controls cover their concern: encryption, access, availability, incident response, vendor management.
- Who your sub-processors are and where data is stored.
- How to get the full report quickly, without a sales call.
Publish openly
Certification badges with dates and scope. Control summaries by domain, ideally with live status rather than a paragraph written last year. The sub-processor list with locations and purpose. Policy titles with last-review dates. A security contact and a vulnerability disclosure process. Uptime history if you make availability commitments.
Gate behind a request
The full SOC 2 report, because the AICPA restricts its distribution to parties who understand the report. The penetration-test executive summary. Detailed architecture and data-flow diagrams. Completed questionnaires. A click-through NDA and an email address is enough friction; a sales call is too much.
Mistakes that cost deals
- A badge with no date, which reads as expired.
- Controls described in the future tense.
- A “request access” form that goes to a sales queue with a three-day turnaround.
- A sub-processor list that does not match the DPA.
Keeping it current
The trust center should be a view of your compliance record, not a separate document. In Certifyi it reads control status, certifications and policy dates from the same system the auditor uses, so it changes when the record changes. Report requests are logged, which also gives you a list of prospects in security review.
Frequently asked questions
Can we publish our SOC 2 report openly?
The AICPA restricts SOC 2 distribution to specified parties. Publish that you hold it, the type and period, and gate the report behind a request with a click-through agreement.
Do we need a trust center before we have SOC 2?
Yes, a small one. Publish your controls by domain, policies with dates and your roadmap to SOC 2. Buyers respect a dated plan more than silence.
How often should the trust center change?
Whenever the record changes. If it is generated from your compliance platform, that is automatic. If it is a web page, review it monthly and after every audit or vendor change.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.