Security

What to publish in a trust center

A good trust center answers the security questionnaire before it is sent. A bad one is a logo wall. Here is what buyers actually look for, what to gate, and how to keep it live.
6 min read · Certifyi compliance team · Updated September 2026
Short answer. Publish your certifications and report types with dates, a summary of your controls by domain, your sub-processor list, your policies’ existence and review dates, and how to report a vulnerability. Gate the full SOC 2 report, penetration-test summary and detailed architecture behind a request with an NDA click-through. Keep it live by generating it from your compliance record, not by editing a web page.

What buyers look for first

Publish openly

Certification badges with dates and scope. Control summaries by domain, ideally with live status rather than a paragraph written last year. The sub-processor list with locations and purpose. Policy titles with last-review dates. A security contact and a vulnerability disclosure process. Uptime history if you make availability commitments.

Gate behind a request

The full SOC 2 report, because the AICPA restricts its distribution to parties who understand the report. The penetration-test executive summary. Detailed architecture and data-flow diagrams. Completed questionnaires. A click-through NDA and an email address is enough friction; a sales call is too much.

Mistakes that cost deals

Keeping it current

The trust center should be a view of your compliance record, not a separate document. In Certifyi it reads control status, certifications and policy dates from the same system the auditor uses, so it changes when the record changes. Report requests are logged, which also gives you a list of prospects in security review.

Frequently asked questions

The AICPA restricts SOC 2 distribution to specified parties. Publish that you hold it, the type and period, and gate the report behind a request with a click-through agreement.

Yes, a small one. Publish your controls by domain, policies with dates and your roadmap to SOC 2. Buyers respect a dated plan more than silence.

Whenever the record changes. If it is generated from your compliance platform, that is automatic. If it is a web page, review it monthly and after every audit or vendor change.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top