Trust Center

Your compliance posture,
published as an API

Choose the frameworks, subprocessors and certificates you’re willing to show, and devguard serves them as one public JSON endpoint any site can fetch. Your trust page keeps your own brand and copy, with live compliance data underneath.

Start for freeBook a conversation
++++
app.devguard.ch / settings / trust
Public
Trust Center
10
items published
Frameworks03
Subprocessors05
Certificates02
GET /api/trust/trust_a1B2c3…
What you publish
JSON · CORS open
ISO 27001
framework · badgeon track
SOC 2 Type II
framework · certifiedPrescient Assurance
GDPR
framework · percentage84%
Amazon Web Services
subprocessoreu-central-1 · Frankfurt
SOC 2 Type II report
certificatedownloadable
Nothing is public unless you add it here — the response is a strict allowlist your own site renders
Every framework
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • Swiss nFADP
How it works

Curate, preview, publish

Nothing is public unless you explicitly add it — you decide what each visitor sees, check the exact payload, then switch it on.

01

Choose exactly what to publish

Add the frameworks, subprocessors and certificates you want public. Everything else in the workspace stays private by default; the Trust Center starts empty and only ever shows what an admin put there.

Three ways to show a framework

Each framework publishes in the mode you pick: a status badge, a live coverage percentage, or a certified assertion with the certifying body and date. A framework that isn’t far enough along is never published as a badge or percentage, so what visitors see is always defensible.

02

Preview what crosses the wire

The preview shows the page a visitor could build from your payload, and its Source tab shows the exact JSON. The response is a strict field allowlist — risk scores, owners, storage keys and per-control coverage never leave the workspace.

03

Toggle public and point your site at it

Switch the Trust Center on and share one URL: a public, CORS-open endpoint under an opaque handle you can rotate at any time. Your site fetches it in the browser, renders the arrays in your own markup, and stays current without another deploy.

Why it’s built this way

Built to be quoted, not questioned

Four choices behind how the Trust Center works — each one something you can check, not an adjective.

01

An allowlist, not a filter

The response is a strict field allowlist: the frameworks, subprocessors and certificates you added, and nothing else. Internal data like risk scores, owners and per-control coverage never crosses the wire.

02

Your site, your brand

devguard provides the API only — no hosted page, no embeddable widget, no branding in the payload. You build the page on your own site, so your trust center looks like you, not like your GRC tool.

03

A handle you can rotate

The public URL is an opaque, rotatable handle. Rotating it revokes the old URL immediately, and a disabled Trust Center returns the same 404 as an unknown one, so nobody can probe for unpublished pages.

04

Claims tied to proof

A certified framework can link straight to its downloadable certificate, served through fresh short-lived URLs. Expired certificates drop out automatically, so your page never shows stale proof.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

What your trust page stands on

A trust page is the public face of your ISMS — the statuses, percentages and certificates it shows are maintained in the same workspace.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

The control set behind every status you publish.

coverage86%

Coverage

The live percentages a framework can publish.

Do you encrypt at rest?library
Is MFA enforced?library
94 approved answers reusable

Security questionnaires

The other trust ask buyers send, answered from a library.

86%
Shared with
JDAKMR+3

Reports

The deeper posture story, shared as PDF.

FAQ

The questions evaluators ask.

Is there a hosted trust page or an embeddable widget?

No, and that’s deliberate. devguard serves the data over one public JSON endpoint; the page itself lives on your site, with your brand and your copy. To skip the boilerplate, the in-app preview has a Source tab with a self-contained React component that fetches the API and renders the response — copy it out and restyle it.

What exactly does the endpoint expose?

A generated-at timestamp plus three arrays: frameworks, subprocessors and certificates. Each framework shows only what its display mode allows (a status badge, a coverage percentage, or a certified assertion), a subprocessor location is a name rather than an address, and the response is a strict field allowlist — internal data never leaves the workspace.

How do certificate downloads work?

Each downloadable certificate carries a relative download path that redirects to a fresh, short-lived presigned URL, so a plain link works on your page. The download responds only while the Trust Center is enabled and the certificate is marked downloadable, and the underlying storage key is never exposed.

Can I take it offline again?

Yes, instantly. Toggle the Trust Center off and the endpoint returns 404, indistinguishable from a handle that never existed. Rotating the handle revokes the old URL on the spot while the new one keeps working.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. What you publish stays a curated projection of your workspace; the workspace itself is yours and exportable in full at any time, with no lock-in.

Publish your posture, keep your brand

Add what you’re willing to show, preview exactly what’s exposed, and give your site one URL to render — a trust page that updates itself instead of a PDF that goes stale.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free