Skip to main content

How-to

How to read a trust centre in ten minutes

Vanta, Drata and SafeBase trust centres all look alike. What each section actually proves, which badges are claims, what freshness signals matter, and how to get the facts out without requesting access.

Solomon AmosPublished 10 Sep 2026Updated 18 Sep 202610 min read

A laptop showing an analytics dashboard
Photo by Luke Chesser on Unsplash

Most B2B vendors now publish a trust centre, usually hosted by a compliance platform. They share a layout: a row of framework badges, a list of controls grouped by category, a documents section behind a request form, and a subprocessor list. CertReports captures these pages nightly for thousands of vendors, and the same lessons apply whether you read one by hand or through the index. The platform a vendor uses says almost nothing about its security; what is on the page, and how old it is, says a lot.

30
Trust centres synced into the index by platform integration
Vanta and Drata, 18 September 2026
37.3
Assessment requests the average vendor answers a month
Secureframe, third-party risk statistics
60 to 70%
of questionnaire answers a good trust centre can pre-answer
HyperComply estimate
A mature program on a simple site can outperform a glossy hub with stale PDFs, so focus on freshness (dates on reports, changelog or last-updated cues).

The badge row

Badges identify frameworks; they do not prove status. A SOC 2 badge can mean a Type I from two years ago. An ISO 27001 badge can sit above a 2013-edition certificate. A HIPAA badge means the vendor offers a business associate agreement to some customers on some plans, because no HIPAA certification exists. Treat each badge as the name of a question, then find the answer in the documents or the public registries.

BadgeWhat to look for underneathWhere a third party can confirm it
SOC 2Report type, period end, auditor, criteriaThe auditor, on request
ISO 27001Certificate with edition, scope, sites, certification bodyThe certification body; some national registries
HIPAAThe BAA and which plans it coversNowhere; it is a contract
GDPRDPA with SCCs, EU representative, DPF listingThe DPF list for the listing
FedRAMPStatus, class, agency, assessorThe FedRAMP Marketplace
PCI DSSAOC, services validated, validation dateThe Visa and Mastercard registries
CSA STARLevel, date, underlying standardThe STAR registry
Code on a laptop in a dark room
CertReports captures trust centres by replaying the platform’s own data calls, so a state is a fact on the page, not a guess from a badge image. · Photo by Ilya Pavlov on Unsplash

The controls list

The long list of controls, each with a green tick, is generated by the platform from the vendor’s monitoring integrations. It is useful as a map of what the vendor says it does. It is not evidence that a control operated, and it is not the auditor’s test list. Do not spend your ten minutes here. If the list has a "last updated" stamp, note it; if the stamp is older than the SOC 2 period end, the monitoring is not doing what the page implies.

The documents section

This is where the report, the certificate, the penetration test summary and the policies live, usually behind an NDA click-through. Two things are worth doing before you request access. First, note which documents are listed and their dates; the list itself is public and tells you what exists. Second, check the public registries for the frameworks that have them, because a FedRAMP or DPF status needs no request at all. Request only what the registries cannot give you.

Freshness signals

  • A report date or period end on the SOC 2 entry. No date is a question.
  • An edition on the ISO certificate entry.
  • A "last updated" stamp on the page or a changelog.
  • A penetration test entry with a year. A test older than eighteen months is stale for most buyers.
  • A subprocessor list with a change date and a notification mechanism.

A published subprocessor list with a change notification mechanism is a stronger signal than any badge, because it is specific and checkable. The same goes for a DPA that incorporates the standard contractual clauses and a security.txt file. CertReports records each of these as a dated legal artefact on the vendor page, and a missing artefact is itself a finding: a vendor with no public subprocessor list will struggle with your questionnaire.

ArtefactWhat a good one containsWhat its absence suggests
Subprocessor listNames, purposes, locations, change notice periodThe DPA will be hard to negotiate
DPA2021 SCCs incorporated, UK Addendum where relevantTransfers rest on the DPF alone
security.txtContact, policy, disclosure expectationsNo clear route for vulnerability reports
AI policyWhether customer data trains models, opt-outsAsk before enabling AI features
A team reviewing documents at a table
The ten-minute read replaces the first round of questions, not the contract review. · Photo by Annie Spratt on Unsplash

The ten minutes

  1. 1

    Minute 0 to 2

    Read the badge row and write down the questions each badge raises.

  2. 2

    Minute 2 to 5

    Open the documents list. Note types and dates. Do not request anything yet.

  3. 3

    Minute 5 to 8

    Check the registries for FedRAMP, DPF, PCI DSS and CSA STAR. The CertReports vendor page has them in one place with dates.
  4. 4

    Minute 8 to 10

    Read the subprocessor list and the DPA summary. Decide what you still need to request, which is usually the SOC 2 report and the ISO certificate PDF.

Platform differences that matter to a reader

Vanta and Drata trust centres are generated from compliance automation platforms, so the controls list tracks monitoring integrations and the documents section sits behind the platform’s access flow. SafeBase, now part of Drata, is a dedicated trust centre product with a searchable library and access audit trails. Self-hosted pages vary. None of this changes what to read: the four facts behind each badge, the dates, and the legal artefacts. A well-maintained self-hosted page beats a stale platform page.

Bulk version

Paste a vendor list into the bulk check and get the same reading for every vendor as a table with dates and links, twenty free and five hundred on Buyer Pro.

People also ask

What is a vendor trust centre?

A public page where a vendor publishes its security and compliance posture: framework badges, a controls list, documents such as the SOC 2 report behind a request form, and legal artefacts like the subprocessor list and DPA.

Are trust centre badges reliable?

They identify frameworks, not status. A badge does not show the report type, period, edition or scope. Verify against a registry where one exists and ask for the facts behind the rest.

What should I request from a trust centre?

Only what public sources cannot give you: usually the SOC 2 report and the ISO 27001 certificate PDF. FedRAMP, DPF, PCI DSS and CSA STAR status can be checked on public registries without a request.

Does the trust centre platform matter?

Not much. Vanta, Drata, SafeBase and self-hosted pages all present the same kinds of artefacts. Freshness and specificity matter more than the platform.

Can a trust centre replace a security questionnaire?

Partly. Estimates suggest a good trust portal pre-answers 60 to 70 percent of standard questionnaire items. The rest, mainly exceptions and contractual commitments, still need the vendor.

How does CertReports read trust centres?

By capturing the page and, for platform-hosted centres, replaying the platform’s data calls, then recording each framework fact with a date and a snapshot. Badges alone become vendor-stated rows; linked reports and certificates add the type, period or edition.

trust centreVantaDrataSafeBasevendor review
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like