Understand Controls & Categories in Trust Vault
Who can use this feature
- Supported on Foundation, Growth, and Scale plans
What are Controls?
Controls are specific security measures your organization implements to protect data and systems. Each control represents a security practice, such as "Password Security," "Vulnerability and Patch Management," or "Mobile Device Management." You can showcase these controls on your Trust Portal to show customers and prospects how you safeguard their information.
What are Categories?
Categories organize related controls into logical groups, making it easier for visitors to find relevant security information. Examples include "Security Certifications,” “Access Control,” “Product Security,” “App Security,” "Access Control," "Infrastructure,” etc. These categories help structure your Trust Portal so stakeholders can quickly navigate to the security areas that matter most to them.
Why Add Controls and Categories to Your Trust Portal?
Adding controls and categories to your Trust Portal helps:
- Build customer trust by transparently sharing your security measures
- Streamline security reviews by providing prospects with self-service access to compliance information
- Reduce questionnaire fatigue by proactively addressing common security questions
- Demonstrate compliance with frameworks like SOC 2, ISO 27001, HIPAA, and more
- Accelerate sales cycles by making security documentation readily available
Best Practices
Writing Control Descriptions
- Use clear, non-technical language when possible
- Explain what the control does and why it matters
- Keep descriptions concise but informative (2-4 sentences)
- Use Markdown formatting to improve readability with bullet points or emphasis
Managing Implementation Levels
- Be open about implementation status—transparency builds trust
- Update implementation levels as controls mature
- If a control is "In Progress," consider adding a timeline in the description
Organizing Attachments
- Upload relevant evidence such as audit reports, certifications, or policy documents
- Use descriptive file names so visitors understand what they're requesting
- Mark sensitive documents as private to control access
Customizing Categories
- Rename categories to match the terms your customers use
- Group similar controls together for easier navigation
- Consider creating custom categories if default ones don't fit your security architecture