<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is a trust center?"
title: "What Is a Trust Center"
seoTitle: "What Is a Trust Center? Contents and Examples"
summary: "A trust center is a public web page, usually at trust.yourcompany.com, where a software vendor publishes its security and compliance posture for prospective customers: the frameworks it holds, the controls it runs, its subprocessors, and its policies. Sensitive documents such as a SOC 2 report or penetration test summary sit behind a request gate, typically an NDA or email verification, so the vendor knows who downloaded what. Its job is to answer the questions a buyer's security team would otherwise send as an email or a questionnaire, before they are asked."
publishedAt: "2026-09-14"
keywords:
  - "what is a trust center"
  - "trust center page"
  - "security trust center"
  - "trust portal SOC 2"
pillar: "SOC 2 Tools and Platforms"
faqs:
  - question: "what is the trust center?"
    answer: "A trust center is a vendor's public security page. It lists the compliance frameworks the company holds, summarizes its security controls, names its subprocessors, and offers documents such as a SOC 2 report for download after a request is approved. Buyers use it to start a security review without waiting on email."
  - question: "Should a SOC 2 report be public on a trust center?"
    answer: "No. A SOC 2 report is a restricted-use document under AICPA standards, intended for customers and prospects with a business need. Trust centers publish the fact that the report exists and gate the report itself behind an NDA or an approval step, and they log each download so the vendor can show who received it."
  - question: "Do I need a trust center before I have SOC 2?"
    answer: "It helps, but it is not required. An early trust center can publish the controls you already run, your subprocessor list, and your policies, and state that an audit is in progress with a target date. Buyers read a clear, dated status as a signal the program is real; an empty page or no page at all tells them nothing."
---

## What is a trust center?

A trust center is a **public web page where a software vendor publishes its security and compliance posture** for prospective customers. It usually lives at a subdomain such as trust.yourcompany.com and shows the frameworks the company holds, the controls it runs, its subprocessors, and its policies. Sensitive documents, such as a SOC 2 report, sit behind a request gate. The page exists to answer a buyer's security team before they send the email or the questionnaire.

## What goes on a trust center

Most trust centers split content into what anyone can read and what a buyer has to request.

| Content | Public or gated | Why buyers look for it |
|---|---|---|
| Frameworks held (SOC 2, ISO 27001, HIPAA) | Public | First screen of every vendor review |
| Control summary by area (access, encryption, monitoring) | Public | Lets the reviewer skip half the questionnaire |
| Subprocessor list | Public | Required reading for GDPR and DPA reviews |
| Security policies or policy summaries | Public or gated | Evidence the program is written down |
| SOC 2 report | Gated, usually behind an NDA | Restricted-use document under AICPA standards |
| Penetration test summary or letter | Gated | Proof of independent testing |
| Changelog of security updates | Public | Shows the page is maintained |

The gate matters as much as the content. Each gated download should create an access record: who requested it, who approved it, and when. That record is what you show a customer or an auditor who asks where the report went.

## Why a trust center shortens security reviews

Enterprise security reviews start with the same few requests: the SOC 2 report, the subprocessor list, and a questionnaire. When those are already published and requestable, the reviewer starts from the page instead of from an email thread, and the questionnaire that follows is shorter because the obvious questions are answered.

Trust pages are still uncommon among smaller vendors. Of 494 B2B SaaS companies Screenata looked at, 101 had a trust page. For a startup in an enterprise deal, a maintained trust center is one of the cheaper ways to look like the more prepared vendor.

## How a trust center stays accurate

A trust center goes stale the same way a policy does: someone publishes it once and the controls change underneath it. The durable approach is to publish from the compliance program itself, so control status, framework status, and the subprocessor list update when the underlying records do.

Screenata includes a Trust Center in every framework program: a branded page on your own domain, published from the controls and evidence in your program, with gated downloads behind approval and email verification and every download logged. Screenata runs $5,988/year per framework ($499/mo) for teams up to 50 employees, with the Trust Center included. See [the Trust Center product page](/product/trust-center).
