New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Governance & evidence

Publishing a trust center

A prospect running security due diligence tends to ask the same handful of questions: which frameworks you align with, whether access reviews are current, whether vendors are risk-assessed, and whether policies are published. A trust center answers them before they are asked, at your own subdomain, in your own branding.

Transcript

A prospect doing security due diligence usually asks the same handful of questions. A trust center answers them before they are asked, at your own address, in your own branding.

Everything starts switched off. Framework completion, access review status, vendor risk summary and published policies are each their own toggle, because a trust center that leaks obligation gaps by default is a support incident, not a growth feature.

Enabling the vendor summary never shows vendor names. It shows counts by risk tier only, which is enough to demonstrate active vendor management without disclosing who your suppliers are. Toggling any of these and saving takes effect immediately on the live page.

Published policies can be marked available on request instead of shown outright, one checkbox per document.

For sensitive files, the digital NDA gate adds a legally-binding step before anyone can download. You can supply your own agreement wording, or leave the standard mutual NDA in place.

The published page itself carries your own branding at your own subdomain, not ours, because a trust page a prospect associates with you is worth more than one that reads as a third-party badge.

A visitor requesting a protected file signs the NDA on the page, and the signature is recorded to your tamper-evident audit log before a single-use download link is issued.

Why this is required

GDPR Article 5(2) requires being able to demonstrate compliance, not merely assert it. A trust center is that demonstration made public and self-service, rather than repeated privately over email with every new prospect.

Publishing the wrong thing by default is a real risk in the other direction, which is why every disclosure here is opt-in rather than on by default.

What EuroCompliant does

Every section starts switched off. Framework completion percentages, access review status, vendor risk summary, and published policies are each their own toggle.

The vendor summary, if enabled, never shows vendor names: only counts by risk tier, enough to demonstrate active vendor management without disclosing who your suppliers actually are.

Published policies and evidence files (SOC 2/ISO reports, pentest evidence) can be marked available on request. With the digital NDA gate enabled, a visitor signs an on-page non-disclosure agreement (name, work email, company, and explicit consent, with their IP recorded) before a single-use download link is issued. Every signature is hashed and written to the tenant's tamper-evident audit log, so you can prove to an auditor exactly who accessed a sensitive file and when.

Walking through it

1

Claim a subdomain

Your trust center is published at eurocompliant.com/trust/your-subdomain.

Open /settings →
2

Choose what to disclose

Framework scores, access review status, vendor risk summary, and published policies are each independent toggles.

Open /privacy-hub →
3

Enable the digital NDA gate

Turn on the NDA gate and add your own legal wording, or use the standard mutual NDA. Mark documents and evidence files as protected.

Open /privacy-hub →
4

Visitors sign and download

A visitor who requests a protected file signs the NDA on the page and downloads it directly; the signature is recorded to your audit chain.

Open /privacy-hub →

The law

Frequently asked

Will my trust center show my vendors' names?

No. The vendor summary, if you enable it, only ever shows counts by risk tier, never vendor names.

Can I take the trust center down after publishing it?

Yes. Every section, and the page itself, can be switched off again at any time; nothing here is a one-way action.

Does a visitor need an account to download a protected document?

No. They sign the NDA on the public page with their name, work email and company. The signature is recorded against the tenant's audit chain and a single-use, time-limited download link is issued immediately. No account, no back-and-forth email.

Is an NDA signature legally meaningful?

The agreement records who signed, from which IP, on what date, and hashes the exact agreement text, so it can be produced as evidence of a binding acceptance. Speak to your legal team about whether a standard mutual NDA covers your use case, and supply your own wording through the custom NDA text field if not.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial