Skip to content

Trust center

A trust center is a public portal: a read-only page, reachable by anyone holding the link and without an account, that surfaces your certifications, published documents and a live-ish view of your compliance posture. It exists so a prospect’s security questionnaire can be answered by a URL instead of a fortnight of email.

Extra → Manage portals, in the Public portals section. Two sub-pages support it: Framework snapshots and Public documents.

Published pages live at /trust/<link-token>. One portal can be marked the Primary trust center, which claims the short /trust URL on your instance — that is the address you put on a website or in a proposal.

Under Public portals, use Add to create a new public portal — or open an existing portal’s Settings and turn on Make this portal public. A public portal only offers public-safe tile kinds:

  • Certification / Document — a badge made of an icon and your label, with optional Valid from and Valid until dates, pointing either at an external link or at an uploaded public document.
  • Framework — a compliance donut built from a framework snapshot, which visitors can click into.
  • External — a plain link out.

In Settings → Trust center you set the Tagline, Logo URL and Accent color, and can mark the portal as the Primary trust center. The Public link panel shows the shareable URL and offers Regenerate link, which revokes the previous one immediately.

A snapshot is a frozen, audit-derived view of one framework’s compliance posture. Nothing on the public page reads your live audit data directly; it reads the snapshot, and the snapshot only changes when you say so.

Create one under Framework snapshots by choosing a Domain, then one of its Audits, then the Implementation groups to mirror (leave it empty to mirror all). Each snapshot captures the result breakdown, the score, the per-requirement tree and the controls covered.

When the underlying audit has moved on, Sync offers Review changes first: a table of current versus proposed values, so you see exactly what the public page would start saying before you choose Apply sync. Per snapshot you also choose what the donut reveals — Score and result, Score only, or Result only.

On the public page, a framework tile renders the donut; clicking it opens a drill-down with the collapsible requirement tree and CSV or Excel export for the visitor.

Certifications, summary reports and policies you are happy to hand out live under Public documents. Upload a file, give it a name and a domain, and reference it from a Certification / Document tile.

Each public document is served from its own isolated public URL, deliberately separate from internal evidence, and is only reachable while a published public portal still references it. Uploading a file is therefore not the same as exposing it — nothing is public until a tile on a published portal points at it.