Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Understand Controls & Categories in Trust Vault

Prev Next

Who can use this feature

  • Supported on Foundation, Growth, and Scale plans

What are Controls?

Controls are specific security measures your organization implements to protect data and systems. Each control represents a security practice, such as "Password Security," "Vulnerability and Patch Management," or "Mobile Device Management." You can showcase these controls on your Trust Portal to show customers and prospects how you safeguard their information.

What are Categories?

Categories organize related controls into logical groups, making it easier for visitors to find relevant security information. Examples include "Security Certifications,” “Access Control,” “Product Security,” “App Security,” "Access Control," "Infrastructure,” etc. These categories help structure your Trust Portal so stakeholders can quickly navigate to the security areas that matter most to them.

Why Add Controls and Categories to Your Trust Portal?

Adding controls and categories to your Trust Portal helps:

  • Build customer trust by transparently sharing your security measures

  • Streamline security reviews by providing prospects with self-service access to compliance information

  • Reduce questionnaire fatigue by proactively addressing common security questions

  • Demonstrate compliance with frameworks like SOC 2, ISO 27001, HIPAA, and more

  • Accelerate sales cycles by making security documentation readily available

Best Practices

Writing Control Descriptions

  • Use clear, non-technical language when possible

  • Explain what the control does and why it matters

  • Keep descriptions concise but informative (2-4 sentences)

  • Use Markdown formatting to improve readability with bullet points or emphasis

Managing Implementation Levels

  • Be open about implementation status—transparency builds trust

  • Update implementation levels as controls mature

  • If a control is "In Progress," consider adding a timeline in the description

Organizing Attachments

  • Upload relevant evidence such as audit reports, certifications, or policy documents

  • Use descriptive file names so visitors understand what they're requesting

  • Mark sensitive documents as private to control access

Customizing Categories

  • Rename categories to match the terms your customers use

  • Group similar controls together for easier navigation

  • Consider creating custom categories if default ones don't fit your security architecture

FAQs


1: Will customers see controls marked as “N/A” or “In Progress”?

Yes, all controls you add to Trust Vault are visible to customers. The implementation level you select will be displayed to help customers understand the current status.

2: What happens if I mark control documents as private?

When you select the “Make All Documents Private” checkbox, any documents you add to the control will require access requests. Visitors can see the control exists, but must request permission to view supporting documents.

3: Can I remove a control from the Trust Portal?

4: How often should I update my controls?

Review your controls quarterly or whenever significant security changes occur, such as completing an audit, achieving new certifications, or implementing major security improvements.