Definition

What is a trust center?

A trust center is a public web page where a company publishes its security, privacy, and compliance posture so a buyer can verify it without asking anyone. It holds the certifications the company carries (SOC 2, ISO 27001), the security documentation behind an access request, the subprocessors it shares data with, the controls it operates, and written answers to the security questions buyers ask most. British English writes the same thing as a trust centre, and the two spellings mean exactly the same page.

What a trust center contains

The sections below are the ones a buyer expects to find, and the ones a Wolfia trust center renders. A page missing several of them is a security page wearing the name.

Certifications and audit reports

The frameworks the company holds, grouped into sections, with the report itself available to anyone who is allowed to download it. SOC 2 Type II and ISO 27001 are the two a B2B buyer looks for first.

Documentation behind an access request

Penetration test reports, policies, and architecture documents that are too sensitive to leave open. A visitor requests access, the company approves or declines, and the download is recorded.

An NDA the buyer signs once

One signature unlocks the gated library rather than one signature per document, and every signature lands in the audit log.

Subprocessors

The third parties that process customer data, what each one is used for, and where it runs. Privacy reviewers and DPAs ask for this list by name.

Controls

The security controls the company operates, grouped by category, written so a reviewer can map them to their own framework instead of reading a certificate and guessing.

Frequently asked security questions

The questions that arrive in every questionnaire, answered on the page. This is the part that actually deflects work, because the buyer gets the answer before they open a spreadsheet.

Updates, and a way to subscribe to them

A dated feed of posture changes, new certifications, and incidents, with an email subscription so a buyer who already reviewed you hears about the next change without checking back.

Custom pages

Room for the things that do not fit a standard section: an AI policy, a regional data residency note, a compliance page for one framework.

A route to a human

A support contact and a vulnerability disclosure contact, so a security researcher and a stuck buyer both have somewhere to go.

Who a trust center is for

It is built for the company selling software, and read by the company buying it. On the selling side it belongs to whoever answers security questions today: a security or GRC team at a larger company, a founder or a sales engineer at a smaller one. Any B2B software company whose deals stall in a security review has the problem a trust center solves.On the reading side it is procurement, vendor risk, and security reviewers, plus the champion inside the buying company who needs to get you through their own process. A trust centre serves the same two audiences in the UK, where the spelling differs and nothing else does.

Trust center vs security page vs trust portal vs compliance page

Trust center

Lets a buyer verify your posture and pull the evidence themselves.Read by: Buyers, procurement, and vendor risk reviewersGating: Public overview, sensitive documents behind an access request and an NDA

Security page

A marketing page that describes your security in prose. It reassures, it does not supply evidence.Read by: Anyone reading your websiteGating: Fully public, nothing to download

Trust portal

The same thing as a trust center. The two names are used interchangeably across the market.Read by: Buyers, procurement, and vendor risk reviewersGating: Same as a trust center

Compliance page

Lists which frameworks you are certified against. It is one section of a trust center, not a substitute for one.Read by: Buyers checking a single boxGating: Usually public, usually no documents

How buyers actually use one

They search for your company name plus "trust center" and land on it before they ever contact your sales team.They check whether you hold the certification their policy requires, and stop there if you do not.They request the SOC 2 report, sign the NDA, and download it without a single email to your security team.They read your subprocessor list against their own approved-vendor list.They copy your published answers into the questionnaire they were told to send, so the questionnaire that reaches you is shorter.They subscribe to updates, so next year’s review starts from what changed rather than from zero.

How to build a trust center

Put it on your own domain

A trust center on trust.yourcompany.com is yours, ranks in search under your brand, and does not send buyers to a vendor subdomain they have never heard of.

Decide what is public and what is gated

Certifications, subprocessors, and control descriptions are usually public. Pen test reports and detailed policies sit behind an access request. Getting this split wrong in either direction costs you: too open and you leak, too closed and the buyer emails you anyway.

Automate the approval decision

Matching an incoming request against your CRM lets current customers and open opportunities through instantly, and routes everyone else to a human. Without this, the trust center is a slower inbox.

Answer the frequent questions on the page

A trust center that only hosts PDFs deflects downloads. A trust center that answers the twenty questions every buyer asks deflects questionnaires.

Keep it current, and say when you did

A stale trust center is worse than none, because a buyer who spots an expired report now doubts everything else on the page. Publish updates and let people subscribe.

Connect it to how you answer questionnaires

The trust center and the questionnaire answers should come from the same source of truth. When they do not, sales and security eventually contradict the public page.

Live trust centers to look at

The fastest way to understand the term is to open one. Every page below is public.
trust.wolfia.comWolfia’s own trust center, running on the product described on this page.
trust.amplitude.comAmplitude runs its trust center on its own domain, on Wolfia.
trust.juicebox.aiJuicebox runs its trust center on Wolfia.

Trust center questions, answered

What is a trust center?

A trust center is a public web page where a company publishes its security, privacy, and compliance posture so a buyer can verify it without asking anyone. It holds the certifications the company carries (SOC 2, ISO 27001), the security documentation behind an access request, the subprocessors it shares data with, the controls it operates, and written answers to the security questions buyers ask most. British English writes the same thing as a trust centre, and the two spellings mean exactly the same page.

What is a trust centre?

A trust centre is the British English spelling of a trust center. It is the same thing: a public page where a company publishes its certifications, security documentation, subprocessors, controls, and answers to common security questions, with the sensitive documents released through an access request. Spelling it centre changes nothing about what the page does.

What is the difference between a trust center and a security page?

A security page describes your security in prose and asks the reader to take your word for it. A trust center supplies evidence: the certifications you hold, the reports a buyer can request and download, the subprocessors you use, and the controls you operate. A security page reassures, a trust center verifies.

Is a trust center the same as a trust portal?

Yes. Trust center and trust portal are two names for the same surface, and vendors use both. Trust center is the more common term in search.

Does a trust center stop buyers sending security questionnaires?

It reduces them, it does not end them. Enterprise procurement teams run standardised vendor risk programmes that were designed before your trust center existed, and many will send their questionnaire regardless. A trust center shortens those questionnaires and removes the easy ones entirely, so plan for both surfaces rather than betting on one.

What should a trust center contain?

Certifications and audit reports, documentation released through an access request, an NDA the buyer signs once, a subprocessor list, control descriptions, answers to the security questions buyers ask most, a dated update feed people can subscribe to, and a contact route for support and vulnerability disclosure.

Should a trust center be on my own domain?

Yes. A trust center on your own subdomain, such as trust.yourcompany.com, is the page buyers find when they search your brand, and it keeps the branding and the search equity with you rather than with a vendor subdomain.

Run your trust center and your questionnaires from one place

Wolfia publishes your trust center on your own domain and answers the questionnaires it does not deflect, both from the same knowledge base, with a citation on every answer.Book a demo