Skip to content
TrustShot

FAQ

Questions, answered plainly.

If something here is not clear enough, that is a fault worth telling us about.

What is a Trust Center?

A public page where a company publishes its security posture — certifications, controls, sub-processors, data-handling commitments and policies — so that prospective customers can review it themselves instead of sending a security questionnaire. Sensitive documents such as a SOC 2 report sit behind verification and an NDA rather than being emailed out.

Do we need to be ISO 27001 or SOC 2 certified to use TrustShot?

No. Many companies publish a Trust Center while certification is still in progress, using it to show the controls already in place and the frameworks they are working towards. Being transparent about where you are is more credible than silence.

Where is our data stored?

In India. All data is stored and processed on infrastructure located in India, and is not replicated or backed up outside Indian territory. If your organisation needs hosting in another region, contact us before signing up.

Can we use our own domain?

Yes. Your Trust Center is available immediately on a TrustShot subdomain, and you can point your own — trust.yourcompany.com — at it with two DNS records. HTTPS certificates are issued and renewed automatically at no extra cost.

How is this different from a GRC platform like Sprinto or Vanta?

A GRC platform runs your internal compliance programme: evidence collection, control monitoring and audit readiness. TrustShot is the outward-facing half — the page your customers read. Many companies run both, and TrustShot works alongside whichever GRC tool you already use.

Does TrustShot help with the DPDP Act?

It gives you the places to publish what the Digital Personal Data Protection Act, 2023 expects to be visible — a named Data Protection Officer, a Grievance Officer, your sub-processor list and your data-retention and deletion commitments. TrustShot is not legal advice and does not make you compliant on its own; it is where you publish the position your counsel has agreed.

We are regulated by the RBI. Does hosting in India actually matter?

For regulated entities it frequently does. RBI guidance on outsourcing and on IT governance sets expectations about where regulated data sits and how third parties are managed. Hosting your Trust Center on infrastructure in India removes one line of questioning that a US-based platform cannot answer.

How does gated document access work?

A visitor enters a work email — free providers such as Gmail are refused — and receives a one-time code. For external visitors an NDA must then be accepted. Access lasts 72 hours, documents open page by page in a watermarked viewer with download and print disabled, and every view is recorded against that person.

Can our sales team share access without involving an admin?

Yes. Anyone who verifies an email on your company domain can grant a named external contact access to specific documents. The grant is logged and visible to your administrators immediately, and can be revoked at any time.

We already have a Trust Center elsewhere. Can we move?

Yes. The content is the same material you have already written — certifications, controls, sub-processors, FAQs and policy links. Moving is mostly copying it across and repointing your DNS, which typically takes an afternoon.

What happens to our data if we stop paying?

Your Trust Center stops being served publicly, and your data is retained for a defined window so you can export it. After that it is permanently deleted, including from backups once they age out. The exact window is stated in your agreement before you pay.