What is a Trust Centre - and does a small supplier need one?

A Trust Centre is a public page that publishes your security position: certifications, policies, sub-processors and how you handle incidents. Whether you need one depends almost entirely on how often you are asked the same questions.

Written by Apexward Assure editorial team
Reviewed by Apexward Assure product team
Last reviewed: 30 August 2026

What one actually is

A Trust Centre is a live page on your own domain that states, publicly and in one place, what a prospective customer would otherwise have to extract from you by questionnaire. In practice that means four things.

  • Certifications and their scope. Cyber Essentials, Cyber Essentials Plus, ISO 27001, the Defence Cyber Certification: which you hold, the certificate number or registry entry, the expiry date, and crucially what the certificate covers. Scope is the part buyers get wrong and the part that matters.
  • Control posture. A short, honest description of how you handle the things people always ask about: authentication and multi-factor, encryption in transit and at rest, backups and restore testing, patching timescales, logging, and how staff are vetted and trained.
  • Sub-processors and data location. Who else touches customer data, what they do, and which country it sits in. For anyone selling into the public sector or a regulated buyer, this is often the first question asked and the last one answered.
  • Documents and contact. Your information security policy, data processing terms, incident notification commitments, and a named route to a human for the questions the page does not cover.

The distinguishing feature is that it is live rather than a PDF. A PDF security pack is a snapshot that starts decaying the moment you email it. A Trust Centre is the current position, which is why buyers increasingly ask for a link instead of an attachment.

Why buyers started asking

Two things changed. Supply chain security moved from a nice-to-have to a contractual requirement across UK public sector procurement and defence, which pushed assurance obligations down through the tiers. A prime contractor that has to evidence its own supply chain will ask you, and their own auditor will ask them how they did it.

At the same time, buyers got tired of the questionnaire round-trip from their own side. A procurement team assessing forty suppliers a year would far rather read a page in ten minutes than issue, chase and reconcile forty spreadsheets. A supplier with a decent Trust Centre often gets a shorter questionnaire, or a request to confirm three specifics rather than answer a hundred and eighty.

Does a small supplier need one?

The honest answer is that it depends, and the deciding factor is repetition.

It earns its keep when you are answering the same questionnaire repeatedly. If security questionnaires reach you more than a handful of times a year, the page pays for itself in recovered hours almost immediately, because most of what you are asked is the same information rendered into someone else’s template. It also earns its keep if you are bidding into regulated or defence supply chains, where being able to send a link during a bid, rather than promising a security pack later, changes how you are perceived at exactly the moment it matters. And it helps if you are selling to companies larger than you, where a procurement team is deciding whether a twenty-person supplier is a risk they can carry.

It is overkill if you have three customers who already trust you, no active pipeline that asks security questions, and no certification to publish. Building a public page nobody visits, and then maintaining it, is worse than not having one. If your assurance load is two questionnaires a year, answer them and get on with your work.

There is a middle case worth naming: you have just achieved Cyber Essentials or ISO 27001 and want the certificate to do commercial work. A minimal Trust Centre is a reasonable way to make it visible, provided you accept that publishing a certificate invites the follow-up question of what it covers.

What to publish, and what to leave off

Publish the things a buyer needs to make a decision: certifications and scope, control summaries at the level of “multi-factor authentication is enforced on all administrative access”, sub-processors, data residency, your incident notification commitment, and policies you are comfortable being read by anyone. Add a last-reviewed date to every section, because an undated claim is worth less than a dated one.

Leave off anything that helps an attacker more than it helps a buyer. That means no internal network diagrams, no product or vendor names for your security tooling, no IP ranges or hostnames, no named individuals below the level of a security contact, and no penetration test reports. A summary letter confirming a test was performed, by whom, and that findings were remediated is the right level. The full report goes under NDA to the buyers who genuinely need it, which is what a gated document request is for.

Do not publish anything you cannot substantiate. A Trust Centre is a public representation of your security posture, and a claim you cannot evidence is a claim that will be tested by someone eventually, usually in a contract negotiation.

The maintenance trap

The most common failure is not a bad Trust Centre. It is a good one that goes stale. A page listing a certificate that expired in March, a sub-processor you stopped using last year, and a policy last reviewed in 2024 actively damages you: it tells a careful buyer that your published claims are not maintained, which is precisely the thing they were trying to assess.

Two things prevent it. First, give every section an owner and a review date, and treat an overdue review as a task rather than a background worry. Second, and more effectively, do not maintain the page separately from the underlying facts. If your certificate expiry date lives in one system and your Trust Centre lives in another, they will diverge. If the page renders the same record your compliance programme uses, it cannot.

Start smaller than you think you should. A page with four accurate sections and a contact address beats twelve sections where three are wrong. You can add as the questions come in, and the questions will tell you what to add.

Where Apexward Assure fits

The Trust Centre module publishes from the same records your compliance programme already keeps, so a certificate renewal or a change of sub-processor updates the public page rather than creating a second thing to remember. You choose what is public, what is available on request, and what stays internal. The page works through login-free links, so buyers reading it and suppliers answering your questionnaires cost you no seats. The platform is free, so trying it costs nothing beyond deciding what you are prepared to say in public.