Glossary

Trust Center

A Trust Center is the space a vendor maintains to publish, permanently and up to date, the elements of its security posture: certifications, audit reports, data location, sub-processor list, policies and contractual commitments.

Why vendors publish one

Answering each customer questionnaire individually costs person-days every month. A Trust Center inverts the logic: publish once, kept current, what every customer asks for. On the buyer side it shortens due diligence by providing immediately the artefacts that otherwise arrive after several follow-ups.

What a buyer should check there

A Trust Center is only useful if it is dated. Three checks: the validity of published certificates (an expired ISO 27001 certificate equals no certificate), the sub-processor list and its last update date, and the actual location of data and backups. A complete Trust Center does not remove the need for questions specific to the intended use — certificate scope, data actually processed, recovery commitments.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account