Trust centres and questionnaires · 9 min read · Updated 2026-07-06
Trust center software: what to publish and what to gate
A guide to public, gated and private trust centre content for buyer security reviews.
Direct answer
Trust centre software lets a SaaS team publish stable security summaries, gate sensitive documents and track access requests. Public content answers common buyer questions without exposing sensitive detail. Gated content can require approval, NDA or expiry where needed.
A good trust centre is not a dumping ground. Every claim needs an owner, source evidence and review date. General information only; this is not legal advice.
Public vs gated trust center content
- Public: security overview, compliance scope, responsible disclosure, high-level subprocessors and FAQs.
- Gated: audit reports, pen test summaries, detailed policies and customer-specific evidence.
- Private: raw screenshots, open findings, internal risks and infrastructure detail.
Security documents
- Publish stable summaries.
- Gate detailed reports.
- Add expiry dates to shared documents.
- Record requester and approval.
Certifications and reports
- Show current certification status only when accurate.
- Gate full reports where required.
- Record scope and report date.
Policies
- Publish summaries of mature policies.
- Gate full policy documents if they contain sensitive detail.
- Keep approval and review dates current.
Subprocessors
- Publish high-level subprocessor list where appropriate.
- Link subprocessors to vendor reviews internally.
- Review changes before customer notification.
Security FAQs
- Answer common questions from reviewed source material.
- Link answers to evidence internally.
- Review after system or policy changes.
NDA-gated materials
- Use access approval for reports, detailed diagrams and sensitive evidence.
- Apply expiry dates.
- Keep an access log.
Access request workflow
- Collect requester, company and reason.
- Route to owner for approval.
- Record shared documents and expiry.
- Revoke access when no longer needed.
Keeping trust center content current
| Area | What to check | Evidence to keep | Owner | Review frequency | Status |
|---|---|---|---|---|---|
| Overview | Security summary is accurate | Approved summary | Security lead | Quarterly | Not started |
| Reports | Report date and scope are current | Audit report metadata | Compliance owner | On report update | Not started |
| Policies | Policy summaries match approved policy | Policy record | Policy owner | Annually | Not started |
| Subprocessors | Supplier list is current | Vendor register | Vendor owner | Quarterly | Not started |
| Access | Gated access is reviewed | Access log | Security lead | Monthly | Not started |
Where Trustega fits
Trustega keeps trust centre material connected to evidence, owners and access workflows so buyers can self-serve reviewed information without uncontrolled sharing.
Common questions
Is this guide legal or certification advice?
No. This guide is for general information and is not legal advice. Use qualified legal, privacy or audit advisers for formal interpretation and assurance decisions.
Can a small SaaS team use this without a GRC team?
Yes. The workflows are designed for lean teams, but each record still needs a named owner, a review date and evidence that matches the actual scope.