SOC 2 Tools and Platforms
What is a trust center?
What is a trust center?
A trust center is a public web page where a software vendor publishes its security and compliance posture for prospective customers. It usually lives at a subdomain such as trust.yourcompany.com and shows the frameworks the company holds, the controls it runs, its subprocessors, and its policies. Sensitive documents, such as a SOC 2 report, sit behind a request gate. The page exists to answer a buyer's security team before they send the email or the questionnaire.
What goes on a trust center
Most trust centers split content into what anyone can read and what a buyer has to request.
| Content | Public or gated | Why buyers look for it |
|---|---|---|
| Frameworks held (SOC 2, ISO 27001, HIPAA) | Public | First screen of every vendor review |
| Control summary by area (access, encryption, monitoring) | Public | Lets the reviewer skip half the questionnaire |
| Subprocessor list | Public | Required reading for GDPR and DPA reviews |
| Security policies or policy summaries | Public or gated | Evidence the program is written down |
| SOC 2 report | Gated, usually behind an NDA | Restricted-use document under AICPA standards |
| Penetration test summary or letter | Gated | Proof of independent testing |
| Changelog of security updates | Public | Shows the page is maintained |
The gate matters as much as the content. Each gated download should create an access record: who requested it, who approved it, and when. That record is what you show a customer or an auditor who asks where the report went.
Why a trust center shortens security reviews
Enterprise security reviews start with the same few requests: the SOC 2 report, the subprocessor list, and a questionnaire. When those are already published and requestable, the reviewer starts from the page instead of from an email thread, and the questionnaire that follows is shorter because the obvious questions are answered.
Trust pages are still uncommon among smaller vendors. Of 494 B2B SaaS companies Screenata looked at, 101 had a trust page. For a startup in an enterprise deal, a maintained trust center is one of the cheaper ways to look like the more prepared vendor.
How a trust center stays accurate
A trust center goes stale the same way a policy does: someone publishes it once and the controls change underneath it. The durable approach is to publish from the compliance program itself, so control status, framework status, and the subprocessor list update when the underlying records do.
Screenata includes a Trust Center in every framework program: a branded page on your own domain, published from the controls and evidence in your program, with gated downloads behind approval and email verification and every download logged. Screenata runs $5,988/year per framework ($499/mo) for teams up to 50 employees, with the Trust Center included. See the Trust Center product page.