Governance & evidence
Publishing a trust center
A prospect running security due diligence tends to ask the same handful of questions: which frameworks you align with, whether access reviews are current, whether vendors are risk-assessed, and whether policies are published. A trust center answers them before they are asked, at your own subdomain, in your own branding.
Transcript
A prospect doing security due diligence usually asks the same handful of questions. A trust center answers them before they are asked, at your own address, in your own branding.
Everything starts switched off. Framework completion, access review status, vendor risk summary and published policies are each their own toggle, because a trust center that leaks obligation gaps by default is a support incident, not a growth feature.
Enabling the vendor summary never shows vendor names. It shows counts by risk tier only, which is enough to demonstrate active vendor management without disclosing who your suppliers are.
Published policies can be marked available on request. A visitor requests one by email and receives a secure link to the document, the same tokenized-link mechanism the vendor questionnaires use.
The published page itself carries your own branding at your own subdomain, not ours, because a trust page a prospect associates with you is worth more than one that reads as a third-party badge.
Why this is required
GDPR Article 5(2) requires being able to demonstrate compliance, not merely assert it. A trust center is that demonstration made public and self-service, rather than repeated privately over email with every new prospect.
Publishing the wrong thing by default is a real risk in the other direction, which is why every disclosure here is opt-in rather than on by default.
What EuroCompliant does
Every section starts switched off. Framework completion percentages, access review status, vendor risk summary, and published policies are each their own toggle.
The vendor summary, if enabled, never shows vendor names: only counts by risk tier, enough to demonstrate active vendor management without disclosing who your suppliers actually are.
Published policies can be marked available on request. A visitor requests one by email and receives a secure link to the document, using the same tokenized-link mechanism vendor questionnaires use.
Walking through it
Claim a subdomain
Your trust center is published at eurocompliant.com/trust/your-subdomain.
Open /settings →Choose what to disclose
Framework scores, access review status, vendor risk summary, and published policies are each independent toggles.
Open /trust-center →Mark policies as requestable
A visitor can request a gated document by email and receives a secure, time-limited link.
Open /trust-center →The law
Frequently asked
Will my trust center show my vendors' names?
No. The vendor summary, if you enable it, only ever shows counts by risk tier, never vendor names.
Can I take the trust center down after publishing it?
Yes. Every section, and the page itself, can be switched off again at any time; nothing here is a one-way action.
Related guides
Vendor self-service due-diligence questionnaires
Send the same risk questionnaire directly to a vendor's own contact, instead of assessing them on their behalf.
Policy versioning and staff acknowledgment
Every regenerated policy keeps its history, and staff sign-off is tracked against the exact version they read.
Approved answer library and auto-fill
Approved answers to security questionnaire questions, reused automatically the next time the same question appears.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial