Governance & evidence
Publishing a trust center
A prospect running security due diligence tends to ask the same handful of questions: which frameworks you align with, whether access reviews are current, whether vendors are risk-assessed, and whether policies are published. A trust center answers them before they are asked, at your own subdomain, in your own branding.
Transcript
A prospect doing security due diligence usually asks the same handful of questions. A trust center answers them before they are asked, at your own address, in your own branding.
Everything starts switched off. Framework completion, access review status, vendor risk summary and published policies are each their own toggle, because a trust center that leaks obligation gaps by default is a support incident, not a growth feature.
Enabling the vendor summary never shows vendor names. It shows counts by risk tier only, which is enough to demonstrate active vendor management without disclosing who your suppliers are. Toggling any of these and saving takes effect immediately on the live page.
Published policies can be marked available on request instead of shown outright, one checkbox per document.
For sensitive files, the digital NDA gate adds a legally-binding step before anyone can download. You can supply your own agreement wording, or leave the standard mutual NDA in place.
The published page itself carries your own branding at your own subdomain, not ours, because a trust page a prospect associates with you is worth more than one that reads as a third-party badge.
A visitor requesting a protected file signs the NDA on the page, and the signature is recorded to your tamper-evident audit log before a single-use download link is issued.
Why this is required
GDPR Article 5(2) requires being able to demonstrate compliance, not merely assert it. A trust center is that demonstration made public and self-service, rather than repeated privately over email with every new prospect.
Publishing the wrong thing by default is a real risk in the other direction, which is why every disclosure here is opt-in rather than on by default.
What EuroCompliant does
Every section starts switched off. Framework completion percentages, access review status, vendor risk summary, and published policies are each their own toggle.
The vendor summary, if enabled, never shows vendor names: only counts by risk tier, enough to demonstrate active vendor management without disclosing who your suppliers actually are.
Published policies and evidence files (SOC 2/ISO reports, pentest evidence) can be marked available on request. With the digital NDA gate enabled, a visitor signs an on-page non-disclosure agreement (name, work email, company, and explicit consent, with their IP recorded) before a single-use download link is issued. Every signature is hashed and written to the tenant's tamper-evident audit log, so you can prove to an auditor exactly who accessed a sensitive file and when.
Walking through it
Claim a subdomain
Your trust center is published at eurocompliant.com/trust/your-subdomain.
Open /settings →Choose what to disclose
Framework scores, access review status, vendor risk summary, and published policies are each independent toggles.
Open /privacy-hub →Enable the digital NDA gate
Turn on the NDA gate and add your own legal wording, or use the standard mutual NDA. Mark documents and evidence files as protected.
Open /privacy-hub →Visitors sign and download
A visitor who requests a protected file signs the NDA on the page and downloads it directly; the signature is recorded to your audit chain.
Open /privacy-hub →The law
Frequently asked
Will my trust center show my vendors' names?
No. The vendor summary, if you enable it, only ever shows counts by risk tier, never vendor names.
Can I take the trust center down after publishing it?
Yes. Every section, and the page itself, can be switched off again at any time; nothing here is a one-way action.
Does a visitor need an account to download a protected document?
No. They sign the NDA on the public page with their name, work email and company. The signature is recorded against the tenant's audit chain and a single-use, time-limited download link is issued immediately. No account, no back-and-forth email.
Is an NDA signature legally meaningful?
The agreement records who signed, from which IP, on what date, and hashes the exact agreement text, so it can be produced as evidence of a binding acceptance. Speak to your legal team about whether a standard mutual NDA covers your use case, and supply your own wording through the custom NDA text field if not.
Related guides
Vendor self-service due-diligence questionnaires
Send the same risk questionnaire directly to a vendor's own contact, instead of assessing them on their behalf.
Policy versioning and staff acknowledgment
Every regenerated policy keeps its history, and staff sign-off is tracked against the exact version they read.
Approved answer library and auto-fill
Approved answers to security questionnaire questions, reused automatically the next time the same question appears.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial