Skip to main content

Managing Your Trust Center

✅ Feature availability: This article discusses Trust Center features, some of which may require an upgrade or add-on. Refer to Vanta Plans and Pricing for details.

Your Trust Center is a branded security portal where you can share your compliance documents and security information with customers. This guide explains how to customize your Trust Center’s content, layout, and access settings.

You can use the Trust Center as a stand-alone tool, even if you’re not using the full Vanta product. However, this setup may limit certain editing or automation options, so some features may not be available and some content will need to be managed manually.

⚙️ User permissions: Trust Admins, Editors, and Admins can manage and edit the Trust Center and configure its settings. Trust Collaborators can view Trust Center pages but can't edit content or access settings. Learn more: User Permissions by Product Area


Trust Center editor

To open the Trust Center editor:

  1. Go to Customer Trust > Overview using the navigation menu in your account.

  2. Click the Edit button to open the Trust Center editor.

  3. Click through each tab of your Trust Center to find the section you want to edit.

  4. Click the pencil icon next to a section to open the editing options.

Video overview

Branding and layout

  • Use the Customize menu on the left of the Trust Center editor to upload a header image or choose the colors and fonts you'd like to use in your Trust Center.

  • Click the Customize layout button in the upper-right of the Trust Center editor to re-organize the sections in each tab of your Trust Center.

  • Click to edit the header content directly (title, description, contact email, and link to privacy policy).

  • Add a welcome message or notice.

Compliance

To list the frameworks your company has achieved:

  1. Open the Trust Center editor.

  2. Next to the Compliance section, click the pencil icon to open the editing options.

  3. In the menu on the left, click the + icon to add the framework and enter the relevant details.

  4. Drag and drop frameworks to reorder how they appear in your Trust Center.

Controls

You can customize the controls you want to share with Trust Center viewers by adding controls to categories and managing control visibility settings.

  1. Open the Trust Center editor.

  2. In the Controls tab, click the pencil icon to open the editing options.

  3. Under Control categories, add control categories and reorder how they appear in your Trust Center.

  4. Select an existing category, then above the table:

    • Click Edit controls to choose which controls to put in it.

    • Click the pencil icon next to the category name to edit it.

Global control visibility settings

At a global level, all controls you add to a category are visible to anyone with Trust Center access. You can configure a status visibility setting to decide how much status detail they see.

To configure a global status visibility setting:

  1. In the upper-right corner, click Configure global control visibility.

  2. Select one of the options for the status visibility setting:

    • Show "OK" controls: Controls that are "OK" are displayed.

    • Show "OK" and unmapped controls: Controls that are "OK" or without evidence mapped are displayed. Only "OK" controls display a green check.

    • Show all controls with status: All controls are visible with status displayed. Controls without evidence mapped will not display a green check.

    • Show all controls without status: All controls are visible with no status displayed.

ℹ️ Note: If you don’t have tagging enabled on your plan, you can only set the global status visibility setting.

Control category visibility settings

If your plan includes tagging, each control category can have its own visibility settings that override the global defaults.

Setting

Options

Category visibility

  • Public: Anyone with access to your Trust Center can see the controls added to this category (default setting for all control categories).

  • Shareable: Only accounts and controls that share the same tag can see the controls added to this category.

Status visibility

  • Use the global default for status visibility (default setting for all control categories).

  • Select a status visibility for the category that overrides the default setting.

💡 Tip: Changing category visibility to shareable hides it from your Trust Center. To make the category visible at the status visibility selected, (1) add a tag to the controls in the category and (2) add the same tag to the accounts you want to have access to those controls. Learn more: Customer Trust Accounts

FAQ

Use Frequently Asked Questions (FAQ) to proactively address questions you get from prospects and customers—like commonly asked security questions, permission requirements, data storage locations, and anything else your sales or security team gets questions about.

To manage the FAQ for your Trust Center:

  1. Open the Trust Center editor.

  2. In the FAQ tab, click the pencil icon to open the editing options.

  3. In the menu on the left, click the + icon to add the question, answer, and metadata for the FAQ.

  4. Drag and drop FAQs to reorder how they appear in your Trust Center.

    • The first 4 FAQ will show on the front page of the Trust Center.

    • Remaining FAQ will display when visitors click the FAQ tab, where you can also copy a direct link to each FAQ you’ve created for easy sharing.

Media

To add YouTube or Vimeo videos to your Trust Center:

  1. Open the Trust Center editor.

  2. In the Media tab, click the pencil icon to open the editing options.

  3. In the menu on the left, click the + icon to add the link, title, and description of the video.

  4. Drag and drop videos to reorder how they appear in your Trust Center.

    • The first 3 videos will show on the front page of the Trust Center.

    • Remaining videos will display when visitors click the Media tab.

Resources

To add resources for people to view or download:

  1. Open the Trust Center editor.

  2. In the Resources tab, click the pencil icon to open the editing options.

  3. In the menu on the left, click the + icon to add a resource from your knowledge base, upload a new resource, or link to a resource hosted elsewhere. Suggested resources:

    • A link to your company's security page

    • SOC 2 report

    • ISO 27001 report

    • Penetration tests

    • Policy report

    • Previously filled-out security questionnaires

    • Anything else you want to include

  4. When editing resource details, add the resource to an existing category. To add a new category, scroll to the bottom of the resource list and click + Add category.

  5. Drag and drop resources to reorder how they appear in your Trust Center.

    • The first 4 resources in each category will show on the front page of the Trust Center.

    • Remaining resources will display when visitors click the Resources tab, where you can also copy a direct link to each resource you’ve added for easy sharing.

Subprocessors

To decide which vendors to display on your Trust Center:

  1. Open the Trust Center editor.

  2. In the Subprocessors tab, click the pencil icon to open the editing options.

  3. In the menu on the left, click the + icon to search existing vendors you want to add to your subprocessors, or click the + New subprocessor button on the right.

  4. Select a subprocessor from the left menu and enter the relevant details.

  5. Drag and drop subprocessors to reorder how they appear in your Trust Center.

    • The first 4 subprocessors will show on the front page of the Trust Center.

    • Remaining subprocessors will display when visitors click the Subprocessors tab.

Updates

In the Updates tab of the Trust Center editor, you can create and manage updates to keep a record of important changes.


Trust Center analytics

  • Go to Customer Trust > Overview using the navigation menu in your account to see a snapshot of your Trust Center’s performance. You’ll see useful information, including total visits, individual page views, resource downloads, pending access requests, and the number of passing controls currently shown in your Trust Center.

  • Go to Customer Trust > Activity using the navigation menu in your account to see details about individual page views per visitor, how Trust Center interactions translate to revenue influenced, and AI-driven insights from customer chats.


Trust Center access requests

Access requests

To manage individual access requests:

  1. Go to Customer Trust > Trust Center using the navigation menu in your account.

  2. Click the Access requests tab.

  3. Select one or more requests and click the Give Access button or Deny button. If you choose to give access, you can set an expiration date.

  4. Click the Request history button for a log of prior approved or denied access requests.

  5. Click the Viewers granted access tab to edit their access details.

💡 Tip: You can control access at the resource level. Manage which individual Trust Center resources are public or require viewers to request access in your Knowledge Base.

Access settings

To manage site-level access or auto-approval settings:

  1. In your account header, click the Settings icon.

  2. In the Settings page menu, scroll to the Features section, select Customer trust, and go to the Trust Center tab.

  3. Scroll to the Configure access section to control whether visitors see your Trust Center by default or must request access.

    • Enable public access to your Trust Center:

      • On: Anyone with the link can access the Trust Center.

      • Off: Only viewers who have been manually invited or approved by a Trust Center admin can access the Trust Center.

    • Enable full access to your Trust Center:

      • On: Show the Request access button. Once approved, viewers can download resources and documentation.

      • Off: Hide the Request access button. Trust Center admins can still send invitations manually to grant access.

  4. Scroll to the Configure auto-approval section to set up rules to automate approval of access requests.

    • You can connect Vanta to your CRM to set conditions for auto-approval.

    • You can automatically approve access at a domain level.

💡 Tip: To automatically approve access requests by email domain, create a Customer Trust Account and enable account-level auto-approval so matching requesters can be automatically approved and associated with that account.


Trust Center data deletion requests

If a Trust Center viewer requests deletion of their personal data, you can fulfill the request directly from Vanta. This workflow revokes the viewer's access and de-identifies matching Trust Center-related records stored in Vanta, and can help you fulfill viewer deletion requests under privacy regulations like GDPR.

Fulfilling deletion requests

Trust Center Admins or higher permissions required. The workflow processes one email address at a time. Vanta uses the email address to identify all matching Trust Center records for that viewer.

To fulfill a deletion request:

  1. In your account header, click the Settings icon.

  2. In the page menu, select Customer Trust.

  3. From the Trust Center tab, scroll to the Right to be forgotten section.

  4. Enter the viewer's email address.

  5. Review the confirmation prompt and confirm the deletion.

Deletion requests are processed in the background, so updates may not appear immediately. If the same person requests access using the same email address again later, the new request will be treated as a new Trust Center record.

What gets de-identified

When you submit a deletion request, Vanta de-identifies the viewer's personal information across the following Trust Center records:

  • Viewer record: Access revoked, name and email de-identified

  • Access requests: Pending requests denied, name and email de-identified in historical requests

  • Update subscriptions: Viewer unsubscribed from all groups, name and email de-identified

  • Update notifications: Viewer's email de-identified in past notification recipient lists

  • Chatbot conversations: Viewer’s email is de-identified as the conversation requester (message content they typed is not de-identified)

  • Event logs: Matching Trust Center viewer and subscriber references are redacted, while audit metadata is preserved

What's still stored

  • If a viewer typed personal information directly into a Trust Center chatbot message, that message content is not automatically de-identified by this workflow—only the viewer's email as the conversation requester is removed.

  • Some historical request metadata may remain after the viewer's name and email are removed. The workflow preserves the underlying record structure for audit purposes while removing identifying information.

  • This workflow applies to Trust Center data stored in Vanta. It does not automatically delete records in connected third-party systems such as your CRM, Slack, or DocuSign. If you need data removed from those systems, do that separately in those tools.


Trust Center settings

To browse available Trust Center settings:

  1. In your account header, click the Settings icon.

  2. In the Settings page menu, scroll to the Features section and select Customer trust.

  3. Click through each tab of the page to find the setting you want to manage. The settings available to you depend on your plan and enabled features.

Setting

Description

Configure access

Make the Trust Center public or private, control whether visitors can request full access, and manage related settings like access expiration and default resource download permissions.

Use a custom domain

Customize the domain name for your Trust Center URL and upload a favicon. Learn more: Creating a custom domain

Configure email sender

Set the name viewers see when they receive emails from your Trust Center.

Access request automation

All access requests require manual approval by default. Connect your CRM to auto-approve based on account data. Individual accounts can override this setting. Learn more: Salesforce, HubSpot

Domain bypass

Viewers from these domains are always approved, regardless of the access request automation setting above.

Configure non-disclosure agreement (NDA)

Require users to agree to your NDA the first time they access your Trust Center, and set up NDA bypass rules. Learn more: DocuSign, Clickwrap

Enable watermark

Adds a dynamic, per-viewer watermark—showing when the document was viewed/downloaded and by whom—to unencrypted PDFs that aren't publicly accessible (private Trust Centers, or access-required resources in a public Trust Center). The watermark is stamped diagonally across every page and shows who accessed the document and when.

Enable AI chatbot

Enable Vanta AI to automatically summarize information for buyers. Choose whether the chatbot is visible to internal users only, authenticated viewers, or all viewers, and whether it's open by default when someone visits your Trust Center. Learn more: Trust Center AI Chatbot

Access request notifications

Choose which admins receive email notifications when a new access request is submitted, managed from your organization's notification settings. Learn more: Notifications

Blocked domains

Block domains from requesting access or subscribing to updates on your Trust Center. Learn more: Blocking domains

Blocked countries

Block countries from requesting access to your Trust Center.

Right to be forgotten

Remove a viewer's personal data from your Trust Center to comply with erasure requests. Learn more: Trust Center data deletion requests