TrustCompliance hub · document vault · security Q&A

Stop rebuilding your
security answers from
scratch, every deal.

Obiguard Trust turns the evidence your Governance and SOC data already produce into a public trust center — certifications, subprocessors, documents, and security Q&A, kept current automatically instead of a slide deck someone updates before a big renewal.

Synced from Governance & SOC. Never hand-typed. Browse live examples in the Trust directory →
Frameworks tracked
5
Access tiers
3public / gated / NDA
Manual updates
0
Link to share
1per deal, per RFP
01 / The Console

What you manage.
Updated on its own, in between.

Certifications, subprocessors, and documents read straight from your live Governance and SOC data. Every view, download, and NDA is written to the same Audit Log — nothing routes through email threads anymore. See the public page this produces →
live · synced from Governance & SOC

Compliance

public · updated live from Governance framework mapping
Overview
Documents
History
SOC 2 Type IIISO/IEC 27001ISO/IEC 42001GDPREU AI Act · in progress
🔒SOC 2 Type II report
Updated 12 Aug
NDA
🔒Penetration test summary
Updated 03 Jul
NDA
Subprocessor list
Updated live
PUBLIC
Data Processing Addendum
Updated 21 May
PUBLIC
Uptime, 90d
99.98%
from SOC
Open questionnaires
4
2 drafted
Subprocessors
12
0 changes, 30d
Access requests
3
awaiting review
02 / Capabilities

Nine capabilities.
One always-current page.

Trust reuses the same evidence Governance and SOC already produce — it doesn’t ask your team to maintain a second copy of the truth for prospects.
01 — CERTIFY

Compliance hub

SOC 2, ISO/IEC 27001, ISO/IEC 42001, GDPR, and EU AI Act readiness — read straight from the same framework mapping Governance already keeps, not re-typed into a slide deck before every renewal.

5 frameworks · synced from Governance
02 — VAULT

NDA-gated document vault

Publish SOC 2 reports, pentest summaries, and DPAs behind a one-click NDA. Each request routes for approval, and every signature and download is timestamped.

Document vault · e-sign NDA
03 — REGISTER

Subprocessor registry

One public, always-current list of subprocessors — with an automatic notice the moment one is added, removed, or changed. No more "accurate as of" PDF.

Auto-notify · on every change
04 — ANSWER

AI-assisted security questionnaires

Drop in a customer’s questionnaire and Trust drafts answers from your live Governance and SOC data. A human reviews and approves every answer before it goes out — nothing ships un-checked.

Draft in minutes · human-approved
05 — LOG

Access requests & audit trail

Every view, download, NDA signature, and access grant writes to the same Audit Log Governance already keeps for policy decisions — one ledger, not a inbox full of one-off requests.

Audit Log · every access, timestamped
06 — WATCH

Live status & uptime

Uptime and incident history pull straight from SOC, so the status page your prospects see is the same one your on-call team watches — not a page someone remembers to update.

Live · sourced from SOC
07 — BRAND

Custom domain & branding

Publish at trust.yourcompany.com with your own logo and colors. Obiguard runs the page; your customers never see ours.

Custom domain · your branding
08 — GATE

Granular access tiers

Mark each item public, sign-in-gated, or NDA-gated — a subprocessor list can stay fully public while a pentest report needs a signature first.

3 tiers · public / gated / NDA
09 — ALERT

Renewal & expiry alerts

Certification renewal dates, pentest cadence, and DPA expiries surface on your dashboard before they lapse — not discovered when a customer asks for a report that’s gone stale.

Expiry alerts · before it lapses
For Sales

Answer the security review before it slows the deal.

  • One link covers most of a typical vendor security review
  • NDA and document requests route themselves, no more email chains
  • AI-drafted questionnaire answers, human-approved before sending
  • Every request logged, so nothing falls through mid-deal
→ For AEs, sales engineers & deal desks
For Security & IT

Stop fielding the same questions on repeat.

  • Certifications and controls read live from Governance
  • Uptime and incident history read live from SOC
  • Granular access tiers keep sensitive reports gated
  • Renewal and expiry alerts before a document goes stale
→ For security & IT leads
For Compliance & Legal

One source of evidence, not five spreadsheets.

  • Subprocessor list changes trigger an automatic notice
  • Every NDA, download, and access grant is audit-logged
  • DPA and pentest cadence tracked against expiry
  • Same evidence ledger Governance already keeps for auditors
→ For Compliance, Legal & GRC
03 / How it works

Turn on Trust.
Never rebuild the deck again.

No separate data entry, no second source of truth. Trust is a view onto data Governance and SOC already collect.
STEP 01 · CONNECT

Minutes, not weeks

Trust reads straight from your existing Governance framework coverage and SOC uptime/incident data. There’s nothing to re-enter.

# nothing to configure twice
→ 5 frameworks synced
→ uptime synced from SOC
STEP 02 · CURATE

Day one

Decide what’s public, what needs a login, and what needs an NDA — SOC 2 reports, subprocessors, pentest summaries, DPAs.

subprocessor list: public
SOC 2 report: nda
pentest summary: nda
→ 3 tiers set
STEP 03 · PUBLISH

When you’re ready

Turn it on at your own custom domain with your logo and colors — your customers never see an Obiguard-branded page.

domain: trust.acmecorp.com
branding: custom
→ page live
STEP 04 · SHARE

Continuously

Drop the link into every deal and RFP. Access requests, NDAs, and questionnaire answers all route through the same page and land in the Audit Log — not an inbox.

3 access requests pending
1 NDA signed today
→ all logged
04 / What ships today

The platform, not the pitch deck.

Trust is a view onto data your organisation already has in Obiguard — it doesn’t ask you to keep a second, hand-maintained copy of your compliance posture for prospects.

5
Frameworks tracked

SOC 2, ISO/IEC 27001, ISO/IEC 42001, GDPR, and EU AI Act readiness — the same coverage Governance already maps.

3
Access tiers

Public, sign-in-gated, and NDA-gated — set per document, not all-or-nothing for the whole page.

0
Manual re-entry

Certifications, subprocessors, and uptime all read live from Governance and SOC — nothing to copy into a second document.

1
Link, every deal

One custom-domain page to drop into every RFP and vendor security review, instead of a fresh export each time.

05 / FAQ

Common
questions.

Don’t see what you’re looking for? Our solutions engineers respond within one business day.

Talk to an SE →
Is Obiguard Trust a replacement for our SOC 2 audit?[01]
No. Trust publishes the evidence an audit already produces — it doesn’t run the audit itself. You still work with your auditor for SOC 2, ISO 27001, or ISO 42001; Trust is where that evidence becomes something a prospect can see without emailing you for a PDF.
How is this different from a shared drive folder of PDFs?[02]
A shared folder goes stale the day someone forgets to re-upload the latest report. Trust reads certifications and uptime live from Governance and SOC, so the page reflects what’s true today, and access to sensitive items is gated and logged instead of a link anyone with the folder can forward.
Does the AI-drafted questionnaire answer just make things up?[03]
No. Drafts are generated only from your own Governance and SOC data — policy coverage, controls, uptime, and existing framework mapping. A human on your team reviews and approves every answer before it’s sent; nothing goes out unapproved.
Can we revoke access to a document after we’ve granted it?[04]
Yes. Access grants, NDA signatures, and document views are all tracked per-viewer, so you can revoke a grant the same way you’d disable an access key — and the revocation itself is written to the Audit Log.
Can we use our own domain?[05]
Yes. Trust can be published at a custom domain — trust.yourcompany.com — with your own logo and color palette. Prospects see your brand, not Obiguard’s.
What if we don’t use Governance or SOC yet?[06]
Trust works best on top of Governance’s framework mapping and SOC’s uptime/incident data, but you can also enter certifications, subprocessors, and documents directly if you’re not yet running either — you’ll just maintain those sections by hand until you connect the underlying product.
Is Trust available now?[07]
Yes — turn it on from your Obiguard dashboard and connect it to your existing Governance and SOC data, or talk to a solutions engineer to scope a rollout.
06 / Get started

Turn your compliance evidence
into proof your customers can
see for themselves.

A 20-minute call with a solutions engineer is enough to scope your rollout. Most customers have a page live within a week of connecting Governance and SOC.

Turn on Trust →Talk to sales ↗Download brochure (PDF) ↓