Joopler docs

Trust Center

Share your security posture and verifiable evidence, publicly or invite-only, on your own domain.

A Trust Center is how you show customers and auditors that your program is real, current, and verifiable, without emailing PDFs.

Where to manage it

Open Trust Center from the left sidebar of your workspace. From there you can:

  • View your Trust Center exactly as visitors see it (even while it is private).
  • Switch between Public and Invite-only.
  • Handle access requests from prospects.
  • Choose the agreements you offer (BAA, DPA, subprocessor list).
  • Connect a custom domain (below).

Public or invite-only

Every workspace can publish a Trust Center that is either:

  • Public. Anyone can view your live framework status, subprocessors, and available agreements.
  • Invite-only. Visitors request access and you approve, so the room is gated.

What it shows

  • Live framework and control status, not a point-in-time snapshot.
  • Your subprocessor list, kept current from your connected environment.
  • Available agreements and documents.
  • An OSCAL export of your program.
  • A link to independently verify any piece of evidence.

Share documents securely

Upload the documents you share under review - your SOC 2 report, BAA, DPA, or a pen-test summary. When someone requests access and you approve them, Joopler emails them a private link to a document room where they download exactly those documents. The links are unique to each approved requester, so nothing sensitive is ever public.

Access is time-boxed. An approved requester's link works for 30 days, not forever. That matters because the link is the credential: anyone who receives a forwarded copy of that email can open the room, so a link that never expires is a document you have permanently published to whoever it reaches.

On the Trust Center page, Live document access lists everyone whose link works right now - which is a different question from who you have approved at some point. From there you can extend another 30 days or revoke immediately. Revoking cuts the link off without deleting the request, so you keep the record of who asked and who approved it.

Every visit and every NDA acceptance is logged in the room access log below it.

Let prospects subscribe to updates

Visitors can subscribe to your Trust Center to be notified when you publish a new document or report. It keeps a buyer's security team warm through a review: when your new SOC 2 lands, the people who care are emailed automatically. Every notification includes a one-click unsubscribe.

Subscribers confirm by email first. Signing up records the address and sends one confirmation link - nothing else. Only after they click does the address join your list. This is deliberate: anyone can type any address into a public box, and without confirmation your Trust Center could be used to send mail to people who never asked, in your name. Your subscriber list shows confirmed addresses, and flags any still awaiting confirmation so a pending signup is never mistaken for a live one.

Choose what your Trust Center offers

Publishing is not all-or-nothing. Under What visitors can do, each extra is its own switch, and all three start on:

  • Self-serve security questionnaire - visitors auto-answer CAIQ or SIG against your live control status. Turn it off if you would rather questionnaires came through your sales team.
  • Transparency log - publishes your evidence-ledger anchor hashes so anyone can confirm the ledger has not been rewritten.
  • Follow this Trust Center - the subscription box described above.

Your control posture is always the core of the page; these decide how much further a visitor can go on their own. Anything switched off is not rendered at all, rather than shown and then refused.

Put it on your own domain

Serve your Trust Center at your own address, like trust.yourcompany.com, fully branded as yours. HTTPS is provisioned and renewed automatically, so there is nothing to manage after setup.

  1. In Trust Center, under Custom domain, enter the domain you want (for example trust.yourcompany.com) and choose Connect domain.

  2. Add the DNS record we show you at your registrar. For a subdomain it is a single CNAME:

    TypeHostValue
    CNAMEtrust.yourcompany.comcname.vercel-dns.com
  3. Choose Check status. Once the record resolves (usually a few minutes), the certificate is issued automatically and the domain flips to Active.

Your Trust Center is then live at your domain, with the same public or invite-only setting you chose. Remove or change the domain any time from the same screen.

Independent verification

Every artifact behind your Trust Center is signed and hash-chained. A visitor can confirm a piece of evidence is authentic and unaltered through the public verifier, without trusting Joopler or logging in. See Verifiable evidence.