Framework status, not a slide
SOC 2, ISO/IEC 27001, GDPR, HIPAA and the rest read from continuous control monitoring. A period that has ended says so on its own, and a control that drifted stops claiming it passes.
read from live monitoring
Trust Center
A public page that reads from continuous control monitoring — framework status, policies, subprocessors, and audit reports released on your approval. Publishing one is a database row: no DNS record, no certificate step, no propagation wait.
trust.safeguard.sh*.trust.safeguard.shtrust.your-own-domain.comWhich frameworks do you hold, what are your policies, who touches our data, and can we read the report. A trust center answers all four before anyone opens a spreadsheet.
SOC 2, ISO/IEC 27001, GDPR, HIPAA and the rest read from continuous control monitoring. A period that has ended says so on its own, and a control that drifted stops claiming it passes.
read from live monitoring
Versioned policies and the subprocessors that touch customer data, each with its purpose and processing location. They change when the platform changes, not when someone remembers the page exists.
versioned · dated
The SOC 2 and pentest reports are never linked publicly. A requester asks, you approve, and one named party gets the file — which carries the sha256 of the exact bytes they received.
gated · hash-verified
The page is indexable, so a prospect searching your name lands on your posture instead of a contact form. The questionnaire that used to open the conversation is already answered.
public · indexable
Controls report continuously onto one measured timeline. The period seals into a document that carries its own SHA-256 — and then it leaves twice: the public slice openly and always, the gated copy only after you approve it, to one named requester.
Each section — posture, frameworks, policies, subprocessors, certifications — carries its own visibility. The API applies it server-side and returns a whitelist, so a field you did not publish cannot reach the page even by mistake.
There is no per-customer DNS record to create. A wildcard already points every <you>.trust.safeguard.sh at this app and the wildcard certificate already covers it, so publishing is a database row — no propagation wait, no certificate step.
Point trust.your-domain.com at us and the page answers on it, with a certificate issued on demand once the hostname is authorised. The page is yours: your logo, your accent, your name in the masthead.
The band below reads live from the public endpoint the moment our own page is published. Until then it says only what we already state everywhere else — no score we have not measured.
Certifications held
Our own live control status is not published to this page yet. When it is, it appears here — the frameworks, the documents and the posture score — rendered by the same components a customer’s page uses, and read from the same public endpoint.
safeguard.trust.safeguard.sh
Whoever landed here followed a half-remembered link. There is no directory to search — ask the company for their trust center link, or check the security section of their website.
A company’s page is at company.trust.safeguard.sh unless they publish it on their own domain. We do not list customers here — who holds a trust center is theirs to disclose, not ours.
Published at company.trust.safeguard.sh, or on the company's own domain such as trust.example.com.
A read-only projection of live control monitoring. An audit period that has ended says so on its own.
SOC 2 and pentest reports are released to a named requester after approval, never linked publicly.
Publishing your trust center is a row in the compliance platform you already run. The page keeps itself current from there.
trust.safeguard.sh