Skip to content
TrustShot

Hosted in India · Built for DPDP & RBI

Answer the security questionnaire before it is sent.

TrustShot gives your company a branded Trust Center — certifications, controls, sub-processors and gated audit reports — in one link you send instead of another spreadsheet.

Or take the 4-step product tour — no signup, runs in your browser.

Publish your posture against the frameworks Indian buyers ask about

ISO/IEC 27001:2022SOC 2 Type IIRBI Cyber Security FrameworkDPDP Act 2023SEBI CSCRFCERT-In DirectionsNIST CSF 2.0PCI DSS v4.0ISO/IEC 27701ISO/IEC 42001

The bottleneck

Every enterprise deal stalls in the same place.

A prospect's security team sends a 200-row questionnaire. Someone on your side stops what they are doing and answers questions they have answered a dozen times, attaches the same ISO certificate, and emails a SOC 2 report into an inbox you will never control again.

Two weeks later it happens again with the next prospect — and the version of your report now circulating has no expiry, no watermark, and no record of who opened it.

A Trust Center turns that repeated work into a link, and turns an uncontrolled email attachment into an access record.

How it works

Live in an afternoon, not a quarter.

  1. 01

    Publish what you already have

    Certifications, security controls, sub-processors, data-handling commitments and policies. Your team fills it in; no engineering work.

  2. 02

    Gate the sensitive material

    SOC 2 reports and pen-test summaries sit behind email verification and an NDA, then open in a watermarked viewer that cannot be downloaded.

  3. 03

    Send one link instead of a spreadsheet

    Prospects self-serve at trust.yourcompany.com. Every view is logged, so you know who looked at what and when.

Your brand, not ours

Your logo. Your colours. Your typeface. Your domain.

A buyer should feel they are on your site, because they are. Upload your logo, set your accent and hero colours, choose a typeface, and serve it all from trust.yourcompany.com with HTTPS included.

  • Logo and brand bar — linking back to your main site
  • Accent and hero colours — set independently, with automatic text contrast
  • Choice of typefaces — from modern sans to classic serif
  • Your own subdomain — certificates issued and renewed for you
  • Section order — drag what your buyers care about to the top
Try your brand on the sample page
NNorthwind PaymentsRequest access

Northwind Payments

Security, privacy and compliance at a glance

ISO 27001 SOC 2 DPDP Act

Why it pays

Built for the people who actually get asked.

Weeks back, per deal

Security review is the slowest stage of most enterprise sales. A reviewer who can answer their own questions does not wait on your team.

Evidence, not assertions

Named certifying bodies, scopes and dates — not a logo wall. Reviewers trust what they can verify.

You see the interest

Which company opened which document, and when. A prospect reading your BCP at 11pm is a signal worth having.

Sales can run it

Any verified employee can grant a client access to a restricted document without waiting for an admin.

Why India matters here

The global tools cannot keep your data here.

SafeBase, Vanta and Drata are US platforms. For a bank, NBFC or payment aggregator answering to the RBI, that is a conversation with your regulator before it is a conversation with your buyer.

See the comparison
  • All data stored and processed in India — no replication outside Indian territory.
  • Named Data Protection Officer and Grievance Officer fields, as the DPDP Act and IT Rules expect.
  • RBI, SEBI, CERT-In and DPDPA presented as first-class frameworks, not a custom add-on.
  • Your own subdomain — trust.yourcompany.com — with HTTPS included.

Restricted documents

Your SOC 2 report stops being an email attachment.

Public documents download freely. Sensitive ones require a verified work email and an accepted NDA, then open page by page in a viewer that blocks download, print and right-click — each page watermarked with the viewer's own email address.

  • Free email providers are refused — work addresses only.
  • Access expires automatically after 72 hours.
  • Every view is logged against a named person.
  • Revoke any grant instantly.
Protected viewPage 3 of 28
reviewer@prospect.com · 09 Oct 2026

Download, print and copy are disabled for this document.

Questions

What buyers ask us first.

What is a Trust Center?

A public page where a company publishes its security posture — certifications, controls, sub-processors, data-handling commitments and policies — so that prospective customers can review it themselves instead of sending a security questionnaire. Sensitive documents such as a SOC 2 report sit behind verification and an NDA rather than being emailed out.

Do we need to be ISO 27001 or SOC 2 certified to use TrustShot?

No. Many companies publish a Trust Center while certification is still in progress, using it to show the controls already in place and the frameworks they are working towards. Being transparent about where you are is more credible than silence.

Where is our data stored?

In India. All data is stored and processed on infrastructure located in India, and is not replicated or backed up outside Indian territory. If your organisation needs hosting in another region, contact us before signing up.

Can we use our own domain?

Yes. Your Trust Center is available immediately on a TrustShot subdomain, and you can point your own — trust.yourcompany.com — at it with two DNS records. HTTPS certificates are issued and renewed automatically at no extra cost.

How is this different from a GRC platform like Sprinto or Vanta?

A GRC platform runs your internal compliance programme: evidence collection, control monitoring and audit readiness. TrustShot is the outward-facing half — the page your customers read. Many companies run both, and TrustShot works alongside whichever GRC tool you already use.

More in the full FAQ.

Stop filling in the same spreadsheet.

Publish your Trust Center this week. Start free, and keep your data in India.