SecureTenant logoSecureTenant
Trust and audit

Prove it outside your organization

Compliance nobody can see does not win deals. This is the part that goes outward, to prospects and to your auditor.

TrustAssurance

Trust page

One address that answers your prospect's security questions.

Every prospect sends the same questionnaire. A trust page puts the answer up front: your scores per standard, your subprocessors, your documents and a list of frequently asked questions, on a public page that lives on your own domain. The scores come straight out of your environment, so you never forward an export that is two months old.

Nothing on this page is visible unless you publish it yourself. That is the reverse of the rest of the platform, and deliberately so. The visitor is a complete stranger rather than someone who already belongs to you, so you choose per section, per document and per vendor what leaves your organization.

AuditorAssurance

Auditor access

Give your auditor access, not your whole environment.

An external auditor gets their own read-only access, limited to exactly the clients they are assessing, with an end date you choose yourself. Once that date passes the access lapses on its own, so it is not something to remember later. Revoking sooner is always possible.

Every action they take lands in the activity log. That replaces the shared login and the export over email that are often the current practice, both of which share the problem that afterwards you cannot show who saw what.

Reporting

Compliance report

One PDF you can simply send along.

The report states the score per standard with the reasoning underneath: what was assessed, what is in order and what is still open. You can put your own logo and colors on it, which matters most when you send it on behalf of a client.

Once generated, a report is kept, even when the underlying measurement has already been cleaned up under the retention policy. A report sitting with an auditor that has vanished on your side would help nobody.