Skip to content

Trust center

Answer customer questions once, defensibly.

A branded trust page provides approved certifications, security practices and evidence from the same controlled state maintained by security and compliance.

Where friction starts today

Every enterprise deal stalls on the same security review

Sales is moving, then the prospect's security team sends a questionnaire and everything stops. Someone digs out the latest certificate, copies answers from the last questionnaire, hunts for the current sub-processor list, and emails a PDF that is out of date the moment a control changes. The same questions come back deal after deal, and each one is answered almost from scratch.

Buyers increasingly expect to check this themselves. A trust page only works when published certifications, practices and subprocessors come from a controlled state. When the outward signal drifts from the real programme, it loses the credibility it is meant to create.

One data model

What you enter here, the other modules already know

Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

Trust Center

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Asset ManagementCurrent at once

Entry to evidence

Every change carries its own proof

An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

What changes for your team

01

Reuse an approved state

A branded page shows selected certifications, framework coverage, BC readiness and security practices. What your team reviews and approves in the workspace is what gets published.

02

Handle sensitive requests under control

Prospects and customers request penetration test reports, certifications and custom questionnaire responses directly from the trust page. Requests route to the right owner inside KaitoSec with gated NDA workflows where needed.

03

Keep security and sales on the same state

Share the trust page in proposals, RFP responses and security reviews. Sales can refer to approved statements while sensitive evidence remains under security and compliance control.

The workflow

01

Certification showcase tied to evidence

Display ISO 27001, SOC 2, TISAX, ISO 22301, ISO 42001 and other certifications with verification details and expiry dates. Each badge links to the underlying compliance evidence so customers see the substance behind the certificate.

02

Prepare questionnaire answers from existing context

Receive questionnaires through the trust page and prepare responses from approved controls, policies and BC documentation. Security reviews, approves and sends.

03

Sub-processor and privacy disclosures

Publish sub-processor list, data retention policies, GDPR disclosures and DPA template directly on the trust page. The same records run your DSMS, so what customers see is what your operation does.

FAQ

Can we control what information is visible on the public trust page?

Yes. Every section is toggled independently. You choose which certifications, frameworks and documents are public. Sensitive items such as full audit reports stay private and are shared only on request through a gated workflow.

How does the trust page help with SOC 2 customer requirements?

Many enterprise customers require a SOC 2 Type II report before signing. The trust page publishes a SOC 2 status summary and exposes the full report to verified requestors through a gated NDA workflow, all managed inside KaitoSec.

Can the trust page be embedded on our own website?

Yes. KaitoSec provides an embeddable widget and a branded subdomain option (for example trust.yourcompany.com). The hosted page can be fully styled to match your brand.

Does the trust page support GDPR transparency requirements?

Yes. Privacy notice, data retention schedule, sub-processor list and DPA template are publishable directly. These sections link to the records that run your DSMS, so disclosures stay accurate when the underlying operation changes.

Relevant foundations