The Trust Center is the artefact the rest of the platform exists to produce: one link you send when an investor or an enterprise buyer asks what you do about security.
It is a ledger of what is proven. It lists your verified controls by area, the method that proved each one, a coarse recency window, verified counts per tier and per framework, and your published documents. It carries no verdict.
What it never shows
No failing control, no not-yet-tested control, no denominator or percentage, no findings, no commit hash, no activity log. A public page that listed your gaps would be a roadmap for an attacker, and a page that showed a fraction would invite the question of what the missing part is, which it cannot answer without becoming that roadmap.
The share link
For a specific buyer, you can issue a share link: time-limited, revocable, watermarked with the viewer’s name, and never indexed. It adds the fractions, counts of controls not yet verified, and open findings as counts by severity and window. It still never shows finding titles or vulnerability identifiers. Every view is logged for you.
What it states about itself
Every Trust Center carries the same fixed wording: the controls were verified by VibeLock from evidence observed at a stated commit, against OWASP ASVS 5.0 and the application-level articles of the GDPR and the EU AI Act, and this does not constitute third-party certification or audit.
That sentence is not configurable. A page that let you quietly drop it would be worth less, not more, because its credibility comes from being visibly unwilling to overclaim.
Where it lives
- Free
- A basic page at a vibelock.ai address: verified controls, verified counts, provenance.
- Starter
- The full page with published documents, and share links for specific buyers.
- Pro and Agency
- Served from your own domain. Agency pages can be white-labelled.