Publish the answers once, and stop being asked the questions.
A public page carrying your certifications, policies and completed standard questionnaires — curated by hand from your library, taken down by itself when something lapses, and with a tier that opens only to somebody you granted.
- Produces
- A public page, and a link that outlives the deal
- Updated
- When you publish; withdrawn hourly on expiry
- Needs
- Library entries marked public and approved
The same forty questions, retyped by a different person each time.
A vendor assessment is mostly not a test. It is a request for documents the company already has and has already sent to somebody else: the certification and its scope, the policy, the list of subprocessors and where they process, the answer about encryption at rest, the answer about how staff are offboarded. The buyer is not being difficult — they have no way to find any of it, so they send a spreadsheet.
What makes it expensive is not the typing. It is that the answers live in six heads and four folders, so each round is a small internal investigation, and the version that goes out is whichever one the person answering happened to find. Two assessments a month, answered slightly differently, is how a company ends up unable to say what it has told people.
And the request usually lands late — after the technical evaluation, when the deal is otherwise won and the only variable left is how fast somebody can turn around a document set.
- Answers that disagreeThe same control described two ways in two assessments, because two people wrote them from memory a month apart.
- A queue in front of the closeProcurement waits on a document that exists, is approved, and is sitting in a folder nobody outside the company can reach.
- Attachments with no way backA certificate emailed to a prospect is a copy you cannot expire, cannot revoke and cannot count.
From a library entry to a page a buyer finds on their own.
Nothing reaches the page automatically. Every step below is somebody choosing, and the machine only ever takes things away.
Choose what goes up
The picker lists what your library holds and, beside each one it will not publish, the sentence saying why.
A candidate list where the blockers are visible rather than mysterious.
Publish a snapshot
Publishing copies the wording as it reads today, with the date and the person who published it.
A page whose contents somebody reviewed, not text assembled at the moment it was read.
Gate what needs an NDA
An entry can go on the page as a count instead of a title, opened by a grant you issue to one requester.
A reader who knows more exists and how to ask, and learns nothing else.
Turn the page on
The page becomes public at a fixed address and is left to be found by search.
A link that goes in the email signature, the datasheet and the vendor form.
Let it retire itself
An entry carrying an expiry comes off the page when the date passes, and warns somebody before it does.
A page that cannot outlive its own evidence.
A published page, including the parts that are not simply published.
Three entries live, one about to lapse, one behind a grant, one the library will not release.
Public, indexable, and readable without an account — which is the point. A buyer who finds this answers most of an assessment without sending one.
- Published
ISO 27001:2022
Certificate and scope statement. Expiry read from the record, not typed in.
- Published
Information security policy
The approved version, snapshotted the day it was published.
- Published
Subprocessors and where they process
Answers the question that otherwise arrives as questions 14 through 19.
- Expiring
SOC 2 Type II
Expires in 31 days. It leaves the page by itself when it does, and somebody is told before that.
- Under NDA
1 document under NDA
A count and no title. Requesters are granted individually, and a grant is revocable.
- Cannot publish
Penetration test — remediation detail
Held at CONFIDENTIAL in the library. Nothing on the publishing screen will lower that for you.
The last two rows are the design. A gated entry shows a count and never a title, and an entry held above public sensitivity is refused here rather than quietly lowered.
Nothing above is a live query or another customer’s pipeline. Every record in it was written for this page, and no buying organization named in it is real.
What it does
Publishing is manual and withdrawal is automatic. That asymmetry is deliberate.
Curated from the library you already keep
Entries come from the same knowledge library your proposals draw on, so the page and the bid quote the same words.
Only what is marked public, and only what is approved
Sensitivity is a precondition and never a trigger. Nothing on the publishing screen will change an entry’s classification for you.
A snapshot, dated
What a buyer read on Tuesday is what you published on Tuesday, whoever has edited the entry since. Where the library has moved on, the screen says so and leaves the choice with you.
Expiry that acts
An entry with a lapse date leaves the page on its own, and you are warned before it does. An expired attestation on a public page is a claim somebody can check.
A tier that opens to one person
Requests arrive with a name and a reason. A grant is a link, is revocable, and stops working on the next request rather than the next cache expiry.
A permanent address
The link is fixed when the page is created, because it will be pasted into forms you will not be able to go back and correct.
Off without dismantling
Taking the page down keeps every entry exactly as it is. Turning it back on restores what was there.
Rendered as text, always
Everything published is stored and shown as plain text, so a page served under your name cannot carry anything but words.
Who publishes one
Different reasons, same page.
A software firm selling into regulated buyers
- Every deal above a certain size ends with a security review, and the reviews arrive at the point where momentum matters most.
- Publishes the certification, the policy set and the subprocessor list, and puts the link in the first email of the procurement stage.
- A share of assessments never arrive, and the ones that do begin with the reviewer having already read the documents.
A services company bidding to public buyers
- Registration portals and prequalification forms ask for the same evidence pack several times a quarter.
- Keeps one page current and answers with its address instead of an attachment.
- One place to update when a certificate renews, rather than a folder whose contents nobody can date.
A subcontractor to larger primes
- Primes ask for evidence during teaming, before there is a contract or an NDA to hang it on.
- Publishes what is public and gates the rest, granting access per prime and revoking when the pursuit closes.
- Material shared without being surrendered, and a record of who was given what.
What it needs
A trust page is part of the response side of the platform rather than an add-on, and one workspace has one page.
- Available on the plans that include the knowledge library, because a trust page publishes from it and has nothing to draw on without it.
- Publishing is restricted to owners and administrators on every plan. Stating a public security posture is not a per-seat permission.
- No limit on how many entries a page carries.
Plan names and allowances are mirrored from the billing catalog. Amounts are on the pricing page, which reads them from Stripe rather than from a number typed into a marketing page.
Questions
Does publishing change anything in my library?
No. Publishing reads an entry and copies it; it never edits one. In particular it will not raise or lower an entry’s sensitivity to make it publishable — that decision affects everywhere else the entry is used, so it stays in the library where those consequences are visible.
What happens when a certification expires?
It comes off the page automatically, within the hour of the expiry passing, and the record that it was published stays. You are warned while it is still within thirty days of lapsing, because renewing it beforehand is better than it disappearing quietly.
Can a visitor see the titles of documents I gated?
No. An anonymous reader is told how many gated entries exist and nothing about what they are. The titles are only visible to somebody holding a grant you issued.
Can I take a grant back?
Yes. Revocation is read on every request rather than cached, so a revoked link stops working immediately rather than when something expires.
Is the page indexed by search engines?
Yes, deliberately. Being findable is most of the value — a buyer reading your posture instead of sending you an assessment only happens if they can find it. The gated tier is never indexed.
Can I change the address later?
No. It is fixed when the page is created, because it is the link that ends up in vendor forms and procurement records you cannot go back and correct.
What if I need to take everything down for a while?
Turn the page off. Every entry stays exactly as it is and comes back unchanged when you turn it on again, so a pause for a legal review is not a re-curation.
Answer it once.
Publish what you have already approved, and let the assessment arrive at a buyer who has read it.