Most B2B vendors now publish a trust centre, usually hosted by a compliance platform. They share a layout: a row of framework badges, a list of controls grouped by category, a documents section behind a request form, and a subprocessor list. CertReports captures these pages nightly for thousands of vendors, and the same lessons apply whether you read one by hand or through the index. The platform a vendor uses says almost nothing about its security; what is on the page, and how old it is, says a lot.
- 30
- Trust centres synced into the index by platform integration
- Vanta and Drata, 18 September 2026
- 37.3
- Assessment requests the average vendor answers a month
- Secureframe, third-party risk statistics
- 60 to 70%
- of questionnaire answers a good trust centre can pre-answer
- HyperComply estimate
A mature program on a simple site can outperform a glossy hub with stale PDFs, so focus on freshness (dates on reports, changelog or last-updated cues).
The badge row
Badges identify frameworks; they do not prove status. A SOC 2 badge can mean a Type I from two years ago. An ISO 27001 badge can sit above a 2013-edition certificate. A HIPAA badge means the vendor offers a business associate agreement to some customers on some plans, because no HIPAA certification exists. Treat each badge as the name of a question, then find the answer in the documents or the public registries.
| Badge | What to look for underneath | Where a third party can confirm it |
|---|---|---|
| SOC 2 | Report type, period end, auditor, criteria | The auditor, on request |
| ISO 27001 | Certificate with edition, scope, sites, certification body | The certification body; some national registries |
| HIPAA | The BAA and which plans it covers | Nowhere; it is a contract |
| GDPR | DPA with SCCs, EU representative, DPF listing | The DPF list for the listing |
| FedRAMP | Status, class, agency, assessor | The FedRAMP Marketplace |
| PCI DSS | AOC, services validated, validation date | The Visa and Mastercard registries |
| CSA STAR | Level, date, underlying standard | The STAR registry |
The controls list
The long list of controls, each with a green tick, is generated by the platform from the vendor’s monitoring integrations. It is useful as a map of what the vendor says it does. It is not evidence that a control operated, and it is not the auditor’s test list. Do not spend your ten minutes here. If the list has a "last updated" stamp, note it; if the stamp is older than the SOC 2 period end, the monitoring is not doing what the page implies.
The documents section
This is where the report, the certificate, the penetration test summary and the policies live, usually behind an NDA click-through. Two things are worth doing before you request access. First, note which documents are listed and their dates; the list itself is public and tells you what exists. Second, check the public registries for the frameworks that have them, because a FedRAMP or DPF status needs no request at all. Request only what the registries cannot give you.
Freshness signals
- A report date or period end on the SOC 2 entry. No date is a question.
- An edition on the ISO certificate entry.
- A "last updated" stamp on the page or a changelog.
- A penetration test entry with a year. A test older than eighteen months is stale for most buyers.
- A subprocessor list with a change date and a notification mechanism.
Subprocessors and legal pages
A published subprocessor list with a change notification mechanism is a stronger signal than any badge, because it is specific and checkable. The same goes for a DPA that incorporates the standard contractual clauses and a security.txt file. CertReports records each of these as a dated legal artefact on the vendor page, and a missing artefact is itself a finding: a vendor with no public subprocessor list will struggle with your questionnaire.
| Artefact | What a good one contains | What its absence suggests |
|---|---|---|
| Subprocessor list | Names, purposes, locations, change notice period | The DPA will be hard to negotiate |
| DPA | 2021 SCCs incorporated, UK Addendum where relevant | Transfers rest on the DPF alone |
| security.txt | Contact, policy, disclosure expectations | No clear route for vulnerability reports |
| AI policy | Whether customer data trains models, opt-outs | Ask before enabling AI features |
The ten minutes
- 1
Minute 0 to 2
Read the badge row and write down the questions each badge raises.
- 2
Minute 2 to 5
Open the documents list. Note types and dates. Do not request anything yet.
- 3
Minute 5 to 8
Check the registries for FedRAMP, DPF, PCI DSS and CSA STAR. The CertReports vendor page has them in one place with dates. - 4
Minute 8 to 10
Read the subprocessor list and the DPA summary. Decide what you still need to request, which is usually the SOC 2 report and the ISO certificate PDF.
Platform differences that matter to a reader
Vanta and Drata trust centres are generated from compliance automation platforms, so the controls list tracks monitoring integrations and the documents section sits behind the platform’s access flow. SafeBase, now part of Drata, is a dedicated trust centre product with a searchable library and access audit trails. Self-hosted pages vary. None of this changes what to read: the four facts behind each badge, the dates, and the legal artefacts. A well-maintained self-hosted page beats a stale platform page.
Bulk version
People also ask
What is a vendor trust centre?
A public page where a vendor publishes its security and compliance posture: framework badges, a controls list, documents such as the SOC 2 report behind a request form, and legal artefacts like the subprocessor list and DPA.
Are trust centre badges reliable?
They identify frameworks, not status. A badge does not show the report type, period, edition or scope. Verify against a registry where one exists and ask for the facts behind the rest.
What should I request from a trust centre?
Only what public sources cannot give you: usually the SOC 2 report and the ISO 27001 certificate PDF. FedRAMP, DPF, PCI DSS and CSA STAR status can be checked on public registries without a request.
Does the trust centre platform matter?
Not much. Vanta, Drata, SafeBase and self-hosted pages all present the same kinds of artefacts. Freshness and specificity matter more than the platform.
Can a trust centre replace a security questionnaire?
Partly. Estimates suggest a good trust portal pre-answers 60 to 70 percent of standard questionnaire items. The rest, mainly exceptions and contractual commitments, still need the vendor.
How does CertReports read trust centres?
By capturing the page and, for platform-hosted centres, replaying the platform’s data calls, then recording each framework fact with a date and a snapshot. Badges alone become vendor-stated rows; linked reports and certificates add the type, period or edition.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
The BAA checklist: what to check before sending PHI to a vendor
Solomon Amos · 9 Sep 2026 · 11 min read
A 30-minute vendor security review using public evidence
Solomon Amos · 30 Aug 2026 · 11 min read