Skip to content

Trust Center

Your security review, answered before it starts.

A public page that reads from continuous control monitoring — framework status, policies, subprocessors, and audit reports released on your approval. Publishing one is a database row: no DNS record, no certificate step, no propagation wait.

  • trust.safeguard.sh
  • *.trust.safeguard.sh
  • trust.your-own-domain.com
◉ continuous watch
Why it matters

A security review is four questions in a trench coat

Which frameworks do you hold, what are your policies, who touches our data, and can we read the report. A trust center answers all four before anyone opens a spreadsheet.

Framework status, not a slide

SOC 2, ISO/IEC 27001, GDPR, HIPAA and the rest read from continuous control monitoring. A period that has ended says so on its own, and a control that drifted stops claiming it passes.

read from live monitoring

Policies and vendors, current

Versioned policies and the subprocessors that touch customer data, each with its purpose and processing location. They change when the platform changes, not when someone remembers the page exists.

versioned · dated

Reports released on approval

The SOC 2 and pentest reports are never linked publicly. A requester asks, you approve, and one named party gets the file — which carries the sha256 of the exact bytes they received.

gated · hash-verified

Found before the call

The page is indexable, so a prospect searching your name lands on your posture instead of a contact form. The questionnaire that used to open the conversation is already answered.

public · indexable

The mechanism

Every control, sealed with its hash

Controls report continuously onto one measured timeline. The period seals into a document that carries its own SHA-256 — and then it leaves twice: the public slice openly and always, the gated copy only after you approve it, to one named requester.

◈ the evidence chain · every control, sealed with its hash
01

Choose what is public

Each section — posture, frameworks, policies, subprocessors, certifications — carries its own visibility. The API applies it server-side and returns a whitelist, so a field you did not publish cannot reach the page even by mistake.

02

It is live immediately

There is no per-customer DNS record to create. A wildcard already points every <you>.trust.safeguard.sh at this app and the wildcard certificate already covers it, so publishing is a database row — no propagation wait, no certificate step.

03

Your own domain, when you want it

Point trust.your-domain.com at us and the page answers on it, with a certificate issued on demand once the hostname is authorised. The page is yours: your logo, your accent, your name in the masthead.

Our trust center

We publish ours on the same page you would

The band below reads live from the public endpoint the moment our own page is published. Until then it says only what we already state everywhere else — no score we have not measured.

Certifications held

  • SOC 2 Type II
  • ISO/IEC 27001
  • GDPR
  • EO 14028 / NIST SSDF

Our own live control status is not published to this page yet. When it is, it appears here — the frameworks, the documents and the posture score — rendered by the same components a customer’s page uses, and read from the same public endpoint.

safeguard.trust.safeguard.sh

Looking for a company?

Trust pages live on their own address

Whoever landed here followed a half-remembered link. There is no directory to search — ask the company for their trust center link, or check the security section of their website.

A company’s page is at company.trust.safeguard.sh unless they publish it on their own domain. We do not list customers here — who holds a trust center is theirs to disclose, not ours.

A page per company

Published at company.trust.safeguard.sh, or on the company's own domain such as trust.example.com.

Current, not a snapshot

A read-only projection of live control monitoring. An audit period that has ended says so on its own.

Reports stay gated

SOC 2 and pentest reports are released to a named requester after approval, never linked publicly.

Answer it once. Keep answering it automatically.

Publishing your trust center is a row in the compliance platform you already run. The page keeps itself current from there.

trust.safeguard.sh