Who should run the trust center?
A trust center is set up once and then run every week. The setup gets an owner; the running usually does not, which is how a page that answered reviews in March is quietly wrong by September.
One named person should own the trust centre: whoever owns security, which in a company without a CISO is often a vCISO, the CTO or a senior engineer. They approve document requests, keep published content accurate and answer the questions it does not. Sales triggers requests and legal owns the NDA, but neither should own the content, because neither can attest that a control is true.
Which roles are involved, and who does what?
| Task | Security owner (vCISO or CTO) | Sales | Legal | Engineering |
|---|---|---|---|---|
| Decide what is published and what is gated | Owns | Consulted | Consulted | Informed |
| Approve report and document requests | Owns | Confirms the deal is real | Owns the NDA template | |
| Keep controls, subprocessors and data locations current | Owns | Tells the owner when something changes | ||
| Answer questions the trust centre does not | Owns | Routes them | Supplies technical detail | |
| Publish incident and status communication | Owns, with leadership | Informed | Consulted on wording | Supplies facts |
| Review everything on a schedule | Owns |
How many hours does running it take?
It scales with the number of buyers reviewing you. A company with a few reviews a quarter may spend an hour or two a week on requests and follow-ups. One selling to banks and enterprises every week can spend three to eight hours, which at a loaded $100 to $150 CAD an hour is $15,000 to $60,000 CAD a year of senior time. TrustCenter's security review cost calculator puts your own numbers into dollars.
When should a vCISO own it?
When you already have one, it is usually the natural fit. A vCISO already owns the security program, the policies and the answers to buyer questionnaires, so the trust centre is the public face of work they do anyway. It makes sense to write trust centre upkeep into the vCISO's scope explicitly: request approvals, a quarterly content review, and a response time for buyer questions. A vCISO contract that does not mention it leaves the work falling between the vCISO and the founder. The vCISO contract checklist covers what to write in.
When you do not have a vCISO and the trust centre is the main security work you need done, a full vCISO retainer is more than the job requires. That is where a managed trust centre fits.
When should you hand it to a managed service?
- The owner is also building the product. Requests wait on the busiest person in the company and deals wait with them.
- Review volume is weekly, not quarterly. Approving requests and answering follow-ups becomes a part-time job.
- Nobody has reviewed the content in six months. Stale subprocessor lists and expired certificates are what reviewers notice first.
- Response time is costing deals. A document request that waits a week can move a signature into the next quarter.
A managed service hosts the trust centre, approves routine requests under rules you set, answers inbound security questions from your approved material and escalates anything new to you. You stay accountable for whether answers are true; the service does the running. TrustCenter explains how managed trust centres work and how to choose between self-managed and managed.
Does the same person answer questionnaires?
They should, because the trust centre and the questionnaire answers have to say the same thing. Two owners means two versions of your encryption answer. If questionnaires currently have no owner, start with who should own security questionnaires and give both jobs to the same person or service.
Common questions
Can sales own the trust centre?
Sales can own the request flow and the relationship with the buyer, but not the content. Only someone who owns security can confirm a control is true, and the trust centre is a statement about your controls.
Should the trust centre be in our vCISO's contract?
Yes, if they are expected to run it. Name the tasks, the review frequency and the response time for buyer questions, so the work is scoped and priced rather than assumed.
How often should trust centre content be reviewed?
At least quarterly, and immediately when something it describes changes: a new subprocessor, a new report, a new data region or an incident. Date every section so reviewers can see it is current.
Find someone to own security
Compare fractional CISOs in Canada, or describe what you need once and get quotes.
Get matched