Skip to main content

Trust Center

The Trust Center is your organization's public-facing security and compliance portal. It showcases your compliance posture, provides gated access to sensitive documents (SOC 2 reports, penetration test summaries), handles visitor access requests, accepts vulnerability disclosures, and serves as a hub for inbound questionnaires — all without exposing internal platform data.

Overview

Access from External → Trust Center in the sidebar. The module has four tabs:

Trust Center admin page showing Designer tab active with drag-and-drop section editor containing Header (Crescendo Health with tagline), About section with security description, Compliance and Certifications section with SOC2, HIPAA, ISO27001 badges, and Security Practices section with Encryption, Access Control, Monitoring and Logging, and Business Continuity. Right panel shows Settings with Publish button, Draft status, History and Reset buttons, and settings links for Brand and Theme, Company Info, Documents, Policies, Sub-Processors, NDA Template, Custom Domain, SEO, plus Display Options toggles
  • Designer — Visual drag-and-drop section editor with settings panel
  • Audience — Access requests, auto-approve rules, subscribers, download log
  • Disclosures — Vulnerability disclosure submissions and notification routing
  • Monitors — Uptime monitoring with incident tracking

A Preview button in the top right lets you see the trust center as visitors will see it.

Designer

The Designer is a two-column layout: the section editor canvas on the left, and the settings panel on the right.

Section Editor

Build your trust center by adding, reordering, and configuring sections. Each section has visibility controls (show/hide), reorder arrows, and a drag handle.

Click + Add Section between any two sections to insert a new one.

Section Types

SectionDescription
HeaderHero banner with company name, tagline, and call-to-action button
AboutCompany overview and security philosophy (rich text)
Compliance & CertificationsFramework badges with certification status, dates, and auditor
DocumentsGated document library (auto-populated from your uploaded documents)
FAQQuestion and answer pairs
Sub-ProcessorsThird-party data processing disclosures (linked to your Vendor records)
Data ResidencyWhere data is stored and processed, with region details
AI TransparencyHow AI is used in your product or service
Security PracticesSecurity controls and measures with icon tiles
PoliciesPublic-facing policy documents (auto-populated from published policies)
UpdatesChangelog and security bulletin feed
Vulnerability DisclosureVDP reporting instructions and submission form
Questionnaire SubmissionInbound security questionnaire intake form
StatusUptime and status page display
ContactContact email and message
CustomFree-form rich text content

Settings Panel

The right panel provides:

  • Publish — Publish the current draft to make it live
  • History — View and restore previous published versions
  • Reset — Discard unpublished changes

Settings links:

SettingDescription
Brand & ThemeColors, fonts, header style, corner style
Company InfoCompany description and security overview
DocumentsManage gated files (SOC 2, ISO certs, pentest reports)
PoliciesSelect which policies to publish on the trust center
Sub-ProcessorsConfigure sub-processor metadata overlay
NDA TemplateDefault NDA text for gated document access
Custom DomainHost on your own domain (e.g., trust.yourcompany.com)
SEOMeta title, description, and Open Graph image

Display Options:

ToggleDescription
Enable Trust CenterMaster on/off toggle for the public trust center
Show Sub-ProcessorsDisplay the sub-processor section
Show Audit HistoryShow audit history timeline

Publishing & Versioning

Changes are saved as drafts until published. Publishing creates a versioned snapshot with an optional note. You can:

  • View previous published versions
  • Compare what changed between versions
  • Restore any previous version
  • See who published each version and when

Documents

Manage gated compliance documents that visitors can request access to download.

Document Types

TypeDescription
SOC 2 ReportService Organization Control audit report
Pentest SummaryPenetration testing executive summary
ISO CertificateISO 27001/42001 certification
HIPAA CertificateHIPAA compliance attestation
PCI CertificatePCI DSS compliance certificate
CustomAny other compliance document

Access Controls

Each document can be configured with:

SettingDescription
Requires NDAVisitor must accept NDA before downloading
NDA TextCustom or default NDA language (can upload NDA PDF)
Access Expiry DaysHow long the download link remains valid
Max DownloadsDownload limit per access grant

Audience

Audience tab showing four collapsible sections: Access Requests (expanded, showing empty state with No access requests yet), Auto-Approve Rules (collapsed), Subscribers (collapsed), and Download Log (collapsed)

Manage who interacts with your trust center across four sections.

Access Requests

When a visitor requests access to a gated document, the request appears here for review.

FieldDescription
Requester NameVisitor's name
Requester EmailVisitor's email address
CompanyVisitor's company
ReasonWhy they're requesting access
StatusPending, Approved, Denied, or Expired

Review workflow:

Visitor requests access → Pending

Admin reviews → Approved (access token emailed) or Denied (with reason)

Visitor downloads → Download count tracked, access expires after configured period

Auto-Approve Rules

Configure automatic approval for trusted domains:

  • Set email domain patterns (e.g., @partner.com)
  • Specify access duration (1–365 days, default 30)
  • Visitors from matching domains skip the review queue

Subscribers

Visitors can subscribe to trust center updates. View subscriber list with email, name, company, and status (Active or Unsubscribed).

Download Log

Audit trail of all document downloads showing the access request, download timestamp, IP address, and user agent.

Disclosures

Vulnerability Disclosure Program (VDP)

Configure your vulnerability disclosure program:

  • Notification emails — Set email addresses for incoming vulnerability reports
  • Program details — Disclosure policy, reporting instructions, PGP key
  • Submission form — Visitors submit reports with title, description, severity, steps to reproduce, and affected URL

VDP submission statuses:

StatusDescription
SubmittedNew report received
AcknowledgedReport acknowledged by your team
InvestigatingActively investigating the report
ResolvedVulnerability has been fixed
ClosedReport closed

Submissions can be assigned to team members, annotated with internal notes, and sent to Vulnerability Management for formal tracking.

Monitors

Configure uptime monitors and track incidents for a public status page:

  • Monitors — Add URLs to monitor with configurable check intervals
  • Incidents — Track and communicate service incidents
  • Status Display — Status section on the trust center shows current system status

Inbound Questionnaires

When enabled, visitors (or your team) can submit security questionnaires through the trust center. Uploaded questionnaires are parsed by AI and auto-answered using your Knowledge Base.

Questionnaire lifecycle:

RECEIVED → PARSING → AI_GENERATING → READY_FOR_REVIEW → IN_REVIEW → COMPLETED → DELIVERED
StatusDescription
ReceivedQuestionnaire uploaded
ParsingAI extracting questions from the document
AI GeneratingAI generating answers from your Knowledge Base
Ready for ReviewAI answers generated, awaiting human review
In ReviewTeam reviewing AI-generated answers
CompletedAll answers reviewed and finalized
DeliveredCompleted questionnaire sent back to requester

Each question item can be reviewed individually with a status of Pending, Approved, Edited, or Skipped. Answers can be regenerated from the Knowledge Base if needed.

See Inbound Questionnaires for the full questionnaire workflow.

Custom Branding

Theme

SettingOptions
Primary ColorHex color for main brand elements
Accent ColorHex color for secondary elements
FontTypography selection
Header StyleSolid, Gradient, Image, or Aurora
Corner StyleRounded, Sharp, or Pill
LogoCompany logo for the header
FaviconBrowser tab icon

Custom Domain

Host your trust center on a custom domain (e.g., trust.yourcompany.com):

  1. Enter your desired domain in Settings
  2. Create the DNS CNAME record shown
  3. Platform verifies DNS propagation automatically
  4. SSL certificate is provisioned via AWS ACM
  5. Domain becomes active once verified

Domain verification statuses: None → Pending DNS → Pending SSL → Active (or Failed)

SEO

FieldDescription
Meta TitleBrowser tab title and search result heading (max 200 chars)
Meta DescriptionSearch result snippet (max 500 chars)
OG ImageSocial sharing preview image

Sub-Processor Management

Disclose third-party data processors by linking Vendor records and adding metadata:

FieldDescription
VendorLinked vendor from your Vendor Management registry
Processing LocationWhere the vendor processes data
Processing TypeWhat type of processing is performed
Transfer MechanismData transfer legal basis (e.g., SCCs, adequacy decision)
Security MeasuresSecurity controls the vendor has in place

Sub-processors can be drag-and-drop reordered for display on the trust center.

Updates & Changelog

Publish security bulletins and compliance updates visible on your trust center:

FieldDescription
TitleUpdate headline
BodyFull content (rich text)
CategoryGeneral, Security, Compliance, Incident, or Feature
PinnedWhether to feature at the top of the feed
Published AtPublication date

Subscribers are notified when new updates are published.