Admin

Dashboard (AI-Forward)

ROI metrics at the top prove value ("9 hours saved this month"). AI proposals are the primary interaction -- "Since yesterday" with accept/review/dismiss per proposal and confidence scoring. Stats and action items follow. AI is the protagonist of the admin experience.

Good morning, Raj

Your trust center has been current for 142 days
Evaluations This Month
3
Avg. Completion
22 min
Est. Time Saved
9 hours
Your trust center is accelerating vendor evaluations
✨ Since Yesterday 2 proposals
Update "Encryption in Transit" description
High confidence · Detected TLS 1.3 enforced in your SSL config
New control proposed: Vulnerability Scanning
Medium confidence · Inferred from security headers and SSL config
Health Score
88
+4 this week
Active Controls
34 / 40
6 gaps remaining
Documents
12
2 uploaded this week
Active Evaluations
3
7 total this month
Needs Your Attention 2 items
SOC 2 Type II expires in 14 days
2 document access requests pending
Recent Activity
2h ago Marcus (fintech.co) downloaded Privacy Policy
5h ago New visitor from healthtech.com
1d ago Pen test report uploaded
Admin

Trust Center Editor

Same sidebar, but clicking "Trust Center" switches to the WYSIWYG split view. Left side shows a live preview with the visitor header. Right panel has health score, checklist, and publishing controls. Edit icons appear on hover.

Preview
Acme Cloud
Security Trust Center
Current
SOC 2 Type II ISO 27001 HIPAA (expiring)
Security Controls ✎ Edit
Data Encryption at Rest
AES-256 via AWS KMS · Verified
Data Encryption in Transit
TLS 1.3 · Verified
Access Control
RBAC + SSO via Okta · Verified
Vulnerability Management
Template · Not verified
Evidence Documents ✎ Edit
Privacy Policy
Public · Updated 3 days ago
Pen Test Report 2025
NDA required · Uploaded 1 day ago
☍ Trust Center Admin
Health Score
88
34/40 controls active
12 documents linked
1 expiring in 14 days
Growth Checklist
Brand confirmed
Template selected
Controls reviewed
Documents uploaded
Verify all controls
Link evidence to controls
Publishing
Last published: 2 hours ago
New Pattern

Task Focus Mode

When the user clicks into a task (e.g., "Review AI-proposed control updates"), the sidebar collapses to an icon rail, giving maximum space. The middle shows a near-exact visitor view with the active element highlighted. The right panel tracks task progress.

The sidebar auto-collapses when entering a task. The user can re-expand it anytime by hovering or clicking the hamburger icon. This ensures focus without losing navigation context.
Live Preview · Task Mode
AC
Acme Cloud
Security Trust Center
Current
SOC 2 Type II ISO 27001 HIPAA (expiring)
Security Controls
Data Encryption at Rest
AES-256 via AWS KMS · Verified
Data Encryption in Transit ← Reviewing
AI suggests: Update from "TLS 1.2+" to "TLS 1.3 enforced, 1.2 deprecated"
Access Control
RBAC + SSO via Okta · Verified
Incident Response
24h SLA · Verified
Vulnerability Management
Template · Not verified
Evidence Documents
Privacy Policy
Public · Updated 3 days ago

Review AI Control Updates

3 proposals from AI analysis
1 of 3 reviewed
Update encryption at rest description
Accepted · "AES-256 via AWS KMS"
2
Update encryption in transit
Reviewing now
3
Add vulnerability scanning control
New control proposed
Current Review
✨ AI Suggestion
Update "Data Encryption in Transit" from "TLS 1.2+" to "TLS 1.3 enforced, TLS 1.2 deprecated Q1 2026"
Source: Scanned config from acmecloud.io SSL certificate and security headers.
Press Esc to exit task mode
Admin

Controls Management

Full list of security controls with status, framework mappings, evidence links, and quick actions. Filter by framework or status. Controls can be AI-proposed, verified, or gaps.

Security Controls

34 active · 6 gaps · 3 AI proposals pending
All (40)
Active (34)
Gaps (6)
AI Proposals (3)
Control
Status
Frameworks
Evidence
Data Encryption at Rest
AES-256 via AWS KMS
● Active
SOC 2ISO 27001
3 linked
Data Encryption in Transit
TLS 1.3 enforced
● Active
SOC 2ISO 27001HIPAA
2 linked
Access Control & SSO
RBAC + Okta SSO integration
● Active
SOC 2ISO 27001
2 linked
Incident Response
24h SLA, documented runbook
● Active
SOC 2
1 linked
Vulnerability Management
Template default · Needs verification
○ Gap
SOC 2ISO 27001
None
✨ Vulnerability Scanning
AI proposed: Based on scan of acmecloud.io
AI Proposal
SOC 2
Auto-detected
Data Backup & Recovery
Template default · Needs verification
○ Gap
SOC 2ISO 27001
None
Admin

Document Library

All evidence documents organized by access tier. Drag-and-drop upload, expiration tracking, and access request management. Documents can be linked to controls as evidence.

Documents

12 documents · 4 public, 5 email-gated, 3 NDA-required
📂
Drop files here or click to upload
PDF, DOC, or images. AI will auto-detect document type and suggest access tier.
All (12)
Public (4)
Email-gated (5)
NDA Required (3)
Document
Tier
Linked Controls
Expires
📄
Privacy Policy
Updated 3 days ago · 245 KB
Public
2 controls
📄
SOC 2 Type II Report
Uploaded 11 months ago · 2.1 MB
Email-gated
8 controls
14 days
📄
ISO 27001 Certificate
Updated 2 months ago · 180 KB
Public
4 controls
11 months
🔒
Penetration Test Report 2025
Uploaded 1 day ago · 3.8 MB
NDA
5 controls
10 months
📄
Data Processing Agreement
Updated 1 month ago · 320 KB
Email-gated
3 controls
Pending Access Requests 2 pending
Marcus Chen · fintech.co
Requested: SOC 2 Report, Pen Test Report · 2 hours ago
Sarah Park · acme.io
Requested: DPA, Pen Test Report · 5 hours ago
Admin

Evaluations

Track who is evaluating your trust center. See visitor activity, document downloads, and evaluation progress. Active evaluations show a timeline of the evaluator's journey.

Evaluations

3 active evaluations · 7 total this month · 12 documents served
Active Evaluations
3
+1 this week
Avg. Time to Complete
4.2 days
-0.8 days vs last month
Documents Served
47
12 this week
Active (3)
Completed (4)
All Visitors (23)
Marcus Chen · fintech.co
Started 2 days ago · Security review for vendor onboarding
📄 4 docs viewed 🔒 2 access requests 🕒 Last active: 2h ago
Sarah Park · acme.io
Started 5 hours ago · Due diligence assessment
📄 2 docs viewed 🔒 1 access request 🕒 Last active: 5h ago
James Rodriguez · healthtech.com
Started 4 days ago · HIPAA compliance check
📄 8 docs viewed 🔒 3 access granted 🕒 Last active: 30m ago
Admin

Trust Center Settings

Complete self-service configuration. The admin controls brand identity, visitor experience, content visibility, access policies, domain, notifications, and AI features. Settings are organized into clear sections with descriptions so admins understand each option without documentation.

This is the full config catalog for the trust center. Every setting shown here represents a discovered configuration need from the UX design process. Settings use contextual controls: toggles for on/off, selects for choices, inputs for text, swatches for colors.
Settings
Brand & Identity
Theme & Appearance
Content & Visibility
Document Access
Domain & SEO
Notifications
AI & Automation
Brand & Identity
Configure how your company appears on the trust center. Your logo and brand colors are shown in the header and shared links.
Company Logo
Displayed in the trust center header. Recommended: 200x200px PNG or SVG with transparent background. Will be shown at 52px in the landing header and 32px in compact view.
📷
Upload
Company Name
Shown in the header and page title. Auto-detected during onboarding scan.
Trust Center Subtitle
Secondary text below your company name. Defaults to "Security Trust Center".
Brand Primary Color
Used in the trust center header gradient and accent elements. Choose a color that represents your brand.
#0891B2 (Teal Cyan)
Hero Headline
Main heading shown on the landing page header. Defaults to "Security & Compliance Overview".
Hero Description
Supporting text below the headline. Auto-generated from your controls count but can be customized.
Company Introduction Card
Shown prominently below the header on the landing page. Gives evaluators immediate context about who you are and your key certifications.
Trust Center Purpose
Short purpose label shown below the company name (e.g., "Security Trust Center", "Vendor Evaluation Portal"). Helps evaluators understand the page's intent.
Company Description
2-3 sentences about your company. Auto-detected from your website during onboarding but fully editable. Shown on the introduction card.
Show Introduction Card
Display the company introduction card with logo, description, and certifications on the landing page. Recommended for first-time evaluator context.
Theme & Appearance
Control the visual theme visitors see. You can offer light mode only, dark mode only, or let visitors choose.
Visitor Theme
Which theme modes are available to visitors on your trust center.
Light only
Dark only
Both
Default Theme
When "Both" is selected above: which theme loads first. "Follow OS" uses the visitor's system preference.
Show Theme Toggle
When "Both" is enabled, show the sun/moon toggle in the header so visitors can switch manually.
Header Pattern
The subtle geometric overlay on the header gradient. Adds visual texture and depth.
Show "Powered by INeedTrust"
Display the INeedTrust attribution badge in the footer. Removing it requires a Pro plan.
Content & Visibility
Choose what information is visible to evaluators on your trust center. We recommend transparency -- gaps shown honestly build more trust than gaps hidden.
Show Gap Count
Display the number of unverified controls alongside active controls (e.g., "34 of 40"). Honest by default.
Gap Display Detail
How much detail about gaps to show visitors. "List" shows gap names, "Count" shows just the number, "Hidden" omits them.
List gaps
Count only
Hidden
Show "Continuously Current" Streak
Display how many consecutive days your trust center has been actively maintained. Builds credibility with evaluators.
Compliance Package Download
Let visitors download all public documents and control mappings as a ZIP for their internal review process.
Visible Frameworks
Which compliance frameworks to display on control mappings. Only frameworks relevant to your certifications should be shown.
Show Certification Expiry Dates
Display when certifications expire in the certification strip. Transparent but may raise questions if not renewed promptly.
Document Access
Configure how visitors request and receive access to gated documents. Balance security with friction-free evaluation.
Default Access Tier for New Documents
When you upload a new document, which access tier should it default to. You can change per document.
Auto-Approve Email-Gated Requests
Automatically grant access when a visitor provides a valid work email. Reduces friction but gives less control over who sees documents.
Require Reason for NDA Requests
Ask visitors to explain why they need NDA-protected documents. Helps you prioritize approvals.
Access Request Notification Email(s)
Email addresses that receive notifications when a visitor requests document access. Separate multiple with commas.
Domain & SEO
Configure your trust center URL and search engine metadata. A custom domain builds credibility with evaluators.
Subdomain
Your trust center is available at this INeedTrust subdomain by default.
🌐 acmecloud.ineedtrust.com
Custom Domain
Point your own domain to the trust center (e.g., trust.acmecloud.io). Requires DNS CNAME configuration. Pro plan required.
🔒 trust.acmecloud.io (not configured)
Page Title (SEO)
The browser tab title and search engine listing title for your trust center.
Meta Description
Search engine description. Auto-generated from your controls and certifications if left empty.
Notifications
Choose how and when you're notified about trust center activity. In-app notifications always appear in the dashboard.
New Evaluation Started
When a visitor begins evaluating your trust center (views multiple pages or requests documents).
Document Access Request
When a visitor requests access to email-gated or NDA-protected documents.
Document Expiring Soon
Receive a reminder when a certification or document is within 14 days of expiration.
AI Proposal Ready
When the AI detects control updates or new controls to propose based on website changes or new scans.
Weekly Activity Digest
A weekly summary of evaluations, document access, and trust center health changes sent every Monday morning.
AI & Automation
Configure how AI assists with your trust center. All AI changes require your review and approval before publishing -- nothing is auto-published.
AI Control Detection
Allow AI to scan your website and public infrastructure to detect security controls and map them to frameworks. This is how your initial trust center was generated.
AI Control Update Proposals
AI monitors your website for changes (SSL upgrades, new policies, header changes) and proposes control description updates. You review each proposal individually.
Periodic Re-scan
How often AI re-scans your website for changes. More frequent scans catch changes faster but may generate more proposals.
Auto-Accept Low-Risk Updates
Automatically accept AI proposals that are minor text refinements (typo fixes, formatting). Substantive changes always require manual review.
Onboarding

The Defining Experience

"Enter your URL, get a trust center." Two states shown: the initial prompt, then the AI scanning state with real-time findings appearing. No sidebar -- full-screen focus on the magic moment.

Your trust center starts with a URL
We'll scan your website, find your security posture, and generate a trust center you can publish in minutes.
We scan public pages, SSL config, headers, and linked policies. Nothing invasive.
🔎
AI-Detected Controls
We find your security practices from public info and map them to frameworks.
Ready in Minutes
Review and confirm -- don't build from scratch. Output before input.
🔒
Honest by Default
Gaps are documented transparently. Trust through honesty, not perfection.
Onboarding · Scanning

AI Analysis in Progress

After entering the URL, the user sees real-time scan progress with findings appearing in the right panel. The output builds before they do anything.

acmecloud.io
Analyzing your security posture
We're building your trust center. This takes about 30 seconds.
Scanning website & SSL configuration
Detecting security headers
Finding linked policies & documents
Mapping to security frameworks
5
Generating trust center
Findings so far
✓ SSL / TLS
TLS 1.3 enforced, HSTS enabled, valid certificate from Let's Encrypt (expires in 84 days)
✓ Security Headers
X-Frame-Options, CSP, X-Content-Type-Options all configured. Missing: Permissions-Policy
✓ Privacy Policy
Found at /privacy-policy. Mentions GDPR, CCPA. Last modified 45 days ago.
✓ Terms of Service
Found at /terms. References data processing and security obligations.
● Mapping frameworks...
Analyzing findings against SOC 2, ISO 27001, and GDPR requirements
Authentication

Sign In / Sign Up

Clean, minimal auth screen. Social login (Google, GitHub) + email/password. The URL scan onboarding can be done WITHOUT signing in first — auth is prompted when they want to save/publish. Light mode.

INeedTrust
Welcome back
Sign in to manage your trust center
or
Don't have an account? Sign up free
By signing in, you agree to our Terms and Privacy Policy
Conversion

Choose Your Plan (Post-Scan)

After the URL scan completes, users see their trust center preview and are prompted to choose a plan. The free tier is positioned as functional but limited. Credit card for Starter/Pro, invoicing for Enterprise. This is the conversion moment.

The scan results are already visible — the user has seen value before this screen. This reduces friction: they're choosing to KEEP what they already have, not buying something abstract.
INeedTrust
acmecloud.io
Skip to Free →
Your trust center is ready. Choose how to publish.
We found 28 controls and 3 documents from your scan. Pick a plan to go live.
Free
$0 / forever
• 5 controls max
• 2 documents max
• INeedTrust subdomain
• "Powered by" mandatory
Most Popular
Starter
$100 / mo
• Unlimited controls
• AI proposals
• Health score
• Visitor analytics
Credit card
Pro
$250 / mo
• Everything in Starter
• Custom domain
• Remove "Powered by"
• Advanced analytics
Credit card
Enterprise
$10-50K / yr
• SSO / SAML
• Data residency
• Multi-brand
• Team collaboration
• API access
Invoicing available
All paid plans include a 14-day free trial. No credit card required to start.
Powered by INeedTrust
Visitor View · Interaction Center

Visitor Interaction Center

A two-way channel on the visitor-facing trust center. Evaluators can submit questions, request documents, track outstanding items, and respond to vendor questionnaires — all without email ping-pong. Replaces scattered communication with a structured interaction hub.

This is the 11th gate in the evaluator critical path. After browsing controls and documents, the evaluator has specific questions or needs. Instead of emailing the vendor (and waiting days), they interact through the trust center. The admin sees this as inbound inquiry signals.
Acme Cloud
Security Trust Center
MR
Marcus Rivera
TechCorp
Your Interactions
Question
Answered
How does Acme Cloud handle data deletion requests under GDPR Article 17?
Data deletion requests are processed within 72 hours. Our automated pipeline ensures complete removal from primary stores and backup propagation within 30 days...
Asked 2 days ago · Answered 1 day ago
Document Request
Pending review
SOC 2 Type II Report (2025)
Requires email verification
Requested 4 hours ago
Questionnaire
3 of 12 answered
Vendor Security Assessment — TechCorp
Sent by Acme Cloud · Due in 5 days
Question
New
What is your incident response SLA for P1 severity?
Asked just now
Ask a Question
Request a Document
Responses typically within 24 hours. All answers reference published trust center content.
Visitor View · Authenticated

Visitor Experience (Logged In)

What the trust center looks like when an evaluator is logged in. The compact header gains a user avatar and notification badge. Document access tiers are resolved (email-gated docs available immediately). A persistent bottom bar shows interaction activity.

Login is never required to browse. But logging in unlocks: email-gated documents without re-entering email, interaction history persistence across sessions, questionnaire responses, and the full Interaction Center. The logged-in state is subtle — just an avatar in the header and resolved access tiers.
Acme Cloud
Security Trust Center
MR
Marcus
🔔 2
You have 1 answered question and 1 document ready for download View interactions →
AC
Acme Cloud Cloud infrastructure · 2,000+ enterprise customers
SOC 2 ISO 27001

Security Controls

34 active controls · 6 gaps documented
Data Encryption at Rest
Verified
AES-256 encryption via AWS KMS. All data at rest is encrypted by default.
SOC 2ISO 27001
Data Encryption in Transit
Verified
TLS 1.3 enforced on all endpoints. TLS 1.2 deprecated Q1 2026.
SOC 2ISO 27001HIPAA
Access Control & SSO
Verified
Role-based access control with Okta SSO integration. MFA enforced for all users.
SOC 2ISO 27001

Evidence Documents

📄
Privacy Policy
Updated 3 days ago · 245 KB
Public
📄
SOC 2 Type II Report
11 months ago · 2.1 MB · Expires in 14 days
Email
📄
Data Processing Agreement
Updated 1 month ago · 320 KB
Email
🔒
Penetration Test Report 2025
1 day ago · 3.8 MB
NDA
Visitor View · Landing

Trust Center Landing (Light)

What evaluators see first. Branded header with 64px logo. Below it, a horizontal company intro banner (logo left, text center, cert badges right) orients the evaluator in 5 seconds without pushing tiles below the fold. HIPAA shows "Renewal in progress" -- honesty with context.

Horizontal banner keeps all drill-down tiles visible on 1080p. Cert badges show validity AND renewal intent. All configurable in Settings > Brand & Identity.
AC
Acme Cloud
Security Trust Center
Last updated: 2 days ago Current
☼ Light ☾ Dark

Security & Compliance Overview

Transparent, evidence-backed security information for your evaluation. 34 of 40 controls addressed with full documentation.

AC
Acme Cloud
Security Trust Center · Vendor Evaluation Portal
Cloud infrastructure provider serving 2,000+ enterprise customers. Transparent, evidence-backed security posture for your evaluation.
SOC 2Valid
ISO 27001Valid
GDPRDPA
HIPAARenewal in progress
34 / 40
Security Controls
Controls mapped to SOC 2, ISO 27001, and SCF frameworks. 6 gaps documented and acknowledged.
12
Evidence Documents
Policies, certifications, and audit reports. Tiered access: 4 public, 5 email-gated, 3 NDA-required.
142 days
Continuously Current
This trust center has been actively maintained and current for 142 consecutive days.
📦
Download Compliance Package
Get all public documents and control mappings as a ZIP for your internal review process.
Visitor View · Inner Page

Trust Center Inner Page (Compact Header)

On inner pages (Controls detail, Documents, etc.) the header shrinks to a single compact bar. Customer logo remains visible but smaller. Navigation tabs let the visitor move between sections. Same gradient and pattern, just tighter.

Acme Cloud
Current

Security Controls

34 active controls · 6 gaps documented · Mapped to 3 frameworks
Data Encryption at Rest
Verified
AES-256 encryption via AWS KMS. All data at rest is encrypted by default.
SOC 2ISO 27001
Data Encryption in Transit
Verified
TLS 1.3 enforced on all endpoints. TLS 1.2 deprecated Q1 2026.
SOC 2ISO 27001HIPAA
Access Control & SSO
Verified
Role-based access control with Okta SSO integration. MFA enforced for all users.
SOC 2ISO 27001
Vulnerability Management
Gap
Not yet verified. This control is on our roadmap for Q2 2026.
Visitor View · Dark Mode

Trust Center Landing (Dark)

Same trust center in dark mode. The toggle in the header lets visitors switch. Dark mode uses the admin palette for content, muted teal gradient in the header. Shown with expanded control and document detail. Same compact header pattern applies in dark mode for inner pages.

Admin configures: theme availability (Light only / Dark only / Both), default theme, and whether the toggle is shown. Visitor preference saved in localStorage, default respects prefers-color-scheme.
AC
Acme Cloud
Security Trust Center
Last updated: 2 days ago Current
☼ Light ☾ Dark

Security & Compliance Overview

Transparent, evidence-backed security information for your evaluation. 34 of 40 controls addressed with full documentation.

AC
Acme Cloud
Security Trust Center · Vendor Evaluation Portal
Cloud infrastructure provider serving 2,000+ enterprise customers. Transparent, evidence-backed security posture for your evaluation.
SOC 2Valid
ISO 27001Valid
GDPRDPA
HIPAARenewal in progress
Security Controls · 34 active, 6 gaps documented
Data Encryption at Rest
Verified
AES-256 encryption via AWS KMS. All data at rest is encrypted by default.
SOC 2ISO 27001
Data Encryption in Transit
Verified
TLS 1.3 enforced on all endpoints. TLS 1.2 deprecated Q1 2026.
SOC 2ISO 27001HIPAA
Access Control & SSO
Verified
Role-based access control with Okta SSO integration. MFA enforced.
SOC 2ISO 27001
Incident Response
Verified
24-hour SLA for P1 incidents. Documented runbook and post-mortem process.
SOC 2
Vulnerability Management
Gap
Not yet verified. This control is on our roadmap for Q2 2026.
Evidence Documents · 12 available
  • 📄
    Privacy Policy
    Updated 3 days ago · 245 KB
    Public
  • 📄
    ISO 27001 Certificate
    Updated 2 months ago · 180 KB
    Public
  • 🔒
    SOC 2 Type II Report
    11 months ago · 2.1 MB · Expires in 14 days
    Email
  • 🔒
    Penetration Test Report 2025
    1 day ago · 3.8 MB
    NDA
Request Document Access
Enter your work email to access email-gated documents, or describe your need for NDA-protected documents.
ANALYTICS

Time Saved Dashboard

How administrators visualize the cumulative value their trust center delivers — time reclaimed from manual security reviews, eliminated email ping-pong, and self-service evaluations.

This page surfaces the ROI metrics that justify continued subscription. Weekly value reports (FR51) are generated from this same data. The goal: make the value undeniable at renewal time.

Time Saved

Your trust center’s cumulative impact on security review efficiency
Total Time Saved
127 hours
Since Jan 2026
This Month
18 hours
+23% vs last month
Evaluations Completed
47
Self-service, no manual work
Avg. Resolution
22 min
Industry avg: 3-4 weeks
Monthly Time Saved Last 6 Months ▾
4h
Oct
8h
Nov
12h
Dec
16h
Jan
21h
Feb
18h
Mar
↗ Trending upward — 79 hours saved total over this period. Month-over-month growth averaging +30%.
Where Time Is Saved
Self-Service Evaluations 72h 56%
Document Auto-Delivery 31h 24%
Questionnaire Elimination 18h 14%
Reduced Follow-Up Emails 6h 5%
Before vs. After INeedTrust
☐ Manual Process
Average 3-4 weeks per evaluation
6-8 email exchanges
Manual document sharing
Repetitive questionnaires
☑ With INeedTrust
22 min average resolution
Self-service access
Automated document delivery
Pre-answered from your trust center
Recent Time-Saving Events 5 events
Acme Corp completed evaluation
Est. 4 hours saved
2h ago
CloudFirst downloaded SOC 2 report
Est. 30 min saved
5h ago
TechVentures self-service evaluation
Est. 3.5 hours saved
Yesterday
SecureStack accessed 3 documents
Est. 45 min saved
Yesterday
DataFlow completed questionnaire
Est. 6 hours saved
2 days ago
Share Your ROI
Generate a branded value report showing how much time and effort your trust center has saved. Perfect for sharing with leadership or during renewal conversations.
Last report sent: Feb 28, 2026
Next scheduled: Mar 7, 2026