A trust center is a central, usually publicly accessible portal through which a vendor provides its security and compliance evidence in a structured, self-service format – from certificates and audit reports to policy excerpts. Unlike a marketing page, it is aimed at scrutinizing third parties: at customers who, as controllers under Art. 28(3)(h) GDPR, may demand evidence and audits, and at procurement and security teams that must assess their direct suppliers under NIS2 (Art. 21(2)(d) of Directive (EU) 2022/2555). An established reference model is the Microsoft Service Trust Portal, which bundles audit reports from external auditors, pentest attestations and whitepapers – some freely accessible, some only after signing in and accepting a non-disclosure agreement.
Trust Center: Self-Service Security Evidence
How to provide certificates, attestations, subprocessor lists and pentest summaries in a structured way – publicly where possible, NDA-protected where necessary.
Security reviews have become a fixture of B2B procurement: anyone buying software or managed services demands certificates, audit reports and information about subcontractors – driven by their own obligations under the GDPR, NIS2 and DORA. Without a central point of reference, vendors answer the same questions in ever new bespoke questionnaires, and confidential documents circulate uncontrolled by email. A trust center consolidates the evidence in one well-maintained place, tiers access by confidentiality and makes the maturity of the vendor's security organization verifiable. This article shows which content belongs in it, how NDA gating works and how the portal interlocks with security questionnaires.
The Essentials at a Glance
Six topic blocks — tap to expand.
NDA gating: tiered access to evidence
The proven tiered model — tap a tier.
- Certificates, SOC 3, policy excerpts and the availability status are freely accessible.
- Not every document belongs in the public domain — the principle: publicly where possible, NDA-protected where necessary.
- After email verification come items such as DPA templates and detailed subprocessor information.
- Behind a non-disclosure agreement sit SOC 2 and pentest reports as well as architecture documentation.
- SOC 2 reports are restricted-use; full pentest reports or the Statement of Applicability give attackers needless insight.
- Platforms implement this with click-through NDAs and logged acceptance — access should be personal, time-limited and logged.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Get started with the Microsoft Service Trust Portal
Documentation of the reference portal: audit reports from external auditors, pentest attestations, and the sign-in and NDA requirement for compliance materials and role-restricted documents.
SOC 3 – SOC for Service Organizations: Trust Services Criteria for General Use Report
Establishes SOC 3 as a freely distributable general-use report, in contrast to the more detailed SOC 2 report, which may only be shared on a restricted basis.
STAR Registry (Security, Trust, Assurance and Risk)
Public registry with CAIQ self-assessments (Level 1, to be updated annually) and audited Level 2 credentials (STAR Certification/Attestation) aimed at reducing repeated vendor questionnaires.
Verordnung (EU) 2016/679 (DSGVO)
Art. 28(2)–(4) governs authorization, notification of changes and the right to object regarding further processors, as well as evidence and audit obligations.
Kriterienkatalog C5:2026
Current version of the cloud criteria catalogue (168 criteria across 17 subject areas); C5 attestations under ISAE 3000 are a common trust center credential in the German market.
Building a trust center or making yours review-ready?
We structure your evidence, define the NDA gating and connect the trust center with your questionnaire processes – happy to start with a no-obligation initial consultation.