Compyl
trust.acme.comPublished from Compyl · updated today
OverviewCertificationsControlsDocumentsSubprocessors
SOC 2Type II · current
ISO 27001certified · 2026
112/114controls passing
SOC 2 Type II reportGated · request + NDA · approved in one click
Request access
Penetration test summaryGated · approval required
Request access
Information Security PolicyPublic summary · v9 · current
Public
Certifications, status & evidence from your live programOne link, always current
Solution · Trust Center

Stop emailing your SOC 2, let your Trust Center answer.

Security reviews stall deals when every prospect emails for your SOC 2, your policies, and a 200-question security review. Compyl’s Trust Center software gives you a branded Trust Center you publish from your GRC platform, certifications, control status, and gated evidence in one place, so stakeholders self-serve, questionnaires shrink, and trust is always one link away.

Last reviewed September 2026 by the Compyl GRC team
One sourcePermission-basedAudit-ready access
The problem

Every security review starts the same way: “can you send your SOC 2?”

When trust lives in email threads and shared drives, prospects wait, your team re-sends the same documents, and deals stall in security review.

Death by questionnaire

Every prospect sends a 200-row security questionnaire, and your team answers the same questions over and over by hand.

Stale, scattered evidence

Your SOC 2, policies, and pen test live in a drive, out of date and emailed one NDA at a time, with no record of who got what.

Security reviews stall deals

While security back-and-forth drags on, the deal sits, and a slow, opaque process erodes the trust you’re trying to prove.

How it works

From email attachments to a self-serve, central trust page

Compyl turns your live GRC data into a public Trust Center, connected, branded, access-controlled, and continuously up to date.

01

Keep it current

Pull certifications, controls, and evidence from your platform.

02

Publish

Launch a branded, public Trust Center on your own domain.

03

Gate access

Set documents public, or behind request, NDA, or approval.

04

Connect

Manage and publish certifications, documents, and status in one place.

05

Deflect & close

Stakeholders self-serve; questionnaires shrink; deals move.

Your security posture

Your security posture in one place, not a PDF in an email thread

Your Trust Center lives in the same platform you use to run your program, so you present certifications and control status from one place, and update and publish them as your posture changes, without building or maintaining a separate microsite.

  • Present your certifications and control status in one place
  • Show progress across multiple frameworks with mapped controls
  • A branded page on your own domain, no microsite to build
  • Update and publish certifications and status from one place
Trust Center · manageOne place · publish when ready
Domaintrust.acme.com
BrandingLogo · colors · tone
Certifications shownSOC 2 · ISO 27001 · HIPAA
Control statusLive from compliance
Policies published6 public summaries
Last publishedToday · 09:12
ISO 27001 surveillance audit passedCertification status updated automatically
Published
NIST CSF readiness · 88%Progress shown with mapped controls
In progress
Access-controlled evidence

Share the SOC 2, to the right people, with a record

Compyl stores every compliance document in one secure, searchable repository and lets you control exactly who sees what. Public content is open; sensitive evidence is gated behind a request, NDA, or approval, and every grant is logged for GDPR and CCPA.

  • One secure, searchable evidence repository
  • Granular, role-based access: public, request, NDA, or approval
  • Prospects request gated reports; you approve in one click
  • Every access logged for GDPR, CCPA, and your own rules
Document requestsAccess-controlled repository
RequestedSOC 2 Type II · prospect
NDA signedClick-through · logged
ApproveSecurity · one click
Granted30-day view access
Northwind Analytics · SOC 2 Type IIRequested by m.chen@northwind.com · NDA accepted
Approve
Paycor · penetration test summaryGranted Sep 12 · expires Oct 12 · 2 views
Active
Every grant logged for GDPR, CCPA and your own rulesAccess log
Fewer questionnaires

Let the Trust Center answer the security review

When prospects and auditors can self-serve your certifications, status, and evidence, most questionnaire and document requests answer themselves. Compyl deflects repetitive requests, shortens security review, and gives auditors direct, permission-based access, so your team gets time back and deals move faster.

  • Self-serve answers deflect repetitive security questionnaires
  • Auditors get direct, permission-based access to evidence
  • Fewer document requests and email threads for your team
  • Faster security reviews, so deals don’t stall on trust
Security review · this quarterRequests deflected by the Trust Center
“Can you send your SOC 2?”Self-served via gated request · no email thread
46
“Which subprocessors touch our data?”Answered by the public subprocessor list
35
200-row security questionnairePre-answered from evidence with Questionnaire Assist
22
Auditor evidence samplingDirect, permission-based access · no attachments
15
Median security review: 11 days → 4 daysDeals move
Why Compyl is different

Built by CISOs as an end-to-end GRC platform, not a standalone trust page

A standalone trust page is a static microsite you maintain by hand. Compyl’s Trust Center is part of the platform that runs your program, so the certifications and evidence you publish come from the real thing. It shows up in five ways.

01

GRC that adapts to complexity

No-code configuration of dashboards, workflows, fields, and reports for every team, without an engineering ticket.

02

End-to-end, built to flex and scale

Governance, risk, compliance, and third-party risk as one connected source of truth, with no ceiling as your program matures.

03

No black box, all your data

125+ proprietary, in-house integrations ingest your full dataset and surface risks single-system checks miss.

04

Automation and AI that augments your team

Agentic AI and 1,500+ blueprints automate evidence and busywork, with humans in the loop on every decision that matters.

05

Quantified risk in financial terms

FAIR models and Monte Carlo simulations put risk in dollars, so the board decides on business impact, not heat-map colors. New in 26.2.

Connected across your program

Your Trust Center is the front door to your whole program

Because your Trust Center lives in the same platform that runs compliance, risk, and vendors, what you publish is backed by what you actually do.

Comply

Compliance & Controls

Publish certifications and control status from your compliance program, so what you share matches what you do.

Explore Compliance →
Govern

Policy Management

Publish approved policies to the Trust Center, so stakeholders always see the current version.

Explore Policy Management →
Risk

Vendor Risk

Show how you manage third-party risk, and reuse the same posture when you’re the vendor being assessed.

Explore Vendor Risk →
Risk

Risk Management

Demonstrate that you monitor risk continuously, so customers see a living program, not a one-time audit.

Explore Risk Management →
Framework coverage

One control library, mapped to every framework it satisfies

Compyl cross-maps controls so a single piece of evidence can satisfy requirements across multiple frameworks at once. Explore any framework below.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
One place
Certifications, status & evidence in a single hub
Permission
Public, request, NDA & approval-based access
Fewer
Security questionnaires & document requests
Audit-ready
Self-serve evidence for customers & auditors

What is a Trust Center?

A Trust Center is a public page where you share your security and compliance posture, certifications, control status, policies, and audit reports, with customers, prospects, partners, and auditors. Compyl gives you one you publish and manage from the GRC platform: present your certifications and control status, store evidence in an access-controlled repository, and let prospects request gated reports like your SOC 2 through a built-in approval and NDA workflow. So stakeholders self-serve, questionnaires shrink, and your team stops emailing documents one NDA at a time.

Checklist

What should a Trust Center include?

Prospects ask the same questions in every security review. A Trust Center answers them before the questionnaire arrives, and gates the documents that need an NDA.

ItemWhy customers askWith Compyl
SOC 2 report and certificationsProof, not claimsGated download with NDA and access log
Live control statusIs the program current or last year’s?Control status published from the GRC platform
PoliciesHow data is handledPublic summaries of the policies you choose
SubprocessorsWho else touches our dataVendor list maintained from vendor risk records
Security questionnaireTheir standard reviewPre-answered from your evidence with Questionnaire Assist
UpdatesHave you changed anything?Change log and subscription
FAQ

Trust Center questions, answered

What is a Trust Center?

A Trust Center is a public, central page where you share your security and compliance posture, certifications, control status, policies, and audit reports, with customers, prospects, partners, and auditors. Instead of emailing documents and filling out questionnaires, stakeholders self-serve transparent, permission-based insight into how you manage security and risk.

What is Compyl’s Trust Center?

Compyl’s Trust Center is a branded security and compliance page you publish and manage from the GRC platform. You present your certifications and control status, store evidence in an access-controlled repository, and let prospects request gated reports like your SOC 2 through a built-in approval and NDA workflow, so stakeholders self-serve and your team isn’t emailing documents one by one. (Compyl runs its own at trust.compyl.com.)

How does a Trust Center reduce security questionnaires?

When prospects and customers can self-serve your certifications, control status, and evidence, most questionnaire and document requests answer themselves. Compyl’s Trust Center deflects repetitive requests, shortens security review, and speeds up deals.

Can I control who sees which documents?

Yes. Compyl’s Trust Center supports granular, role-based access: some content is public, sensitive evidence like a SOC 2 Type II report or penetration test is gated behind a request, NDA, or approval, and every grant is logged, so you stay compliant with GDPR, CCPA, and your own data-handling rules.

How do I keep my Trust Center current?

You manage your Trust Center in Compyl: update certifications, documents, and control status in one place, then publish your changes. Because it lives alongside the program that produces your evidence, what you publish reflects your actual security posture, no separate microsite to rebuild.

Who is Compyl’s Trust Center for?

Security, compliance, and revenue teams that field security reviews, CISOs, GRC managers, and sales engineers who want to demonstrate trust, deflect questionnaires, and accelerate deals with a transparent, central security page.

How is a Trust Center different from a security page?

A static security page lists claims. Compyl’s Trust Center is published from the GRC platform, so control status stays current, and gated documents like a SOC 2 Type II report are released through a request, NDA and approval workflow with a record of every grant.

GRC your way

Turn security from a deal-blocker into a deal-closer

See how Compyl’s Trust Center software gives you a branded Trust Center, certifications, control status, and gated evidence, so stakeholders self-serve and deals move faster.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies