Skip to content

The Trust Hex: A Trust Center for Everything

The trust center was invented by SaaS companies. Someone at a security startup realised that buyers kept asking for the same SOC 2 report, the same penetration test, the same data processing details — and that publishing them on one page ended the email chain before it started. The idea spread until every serious software company had one.

What never happened is the same idea reaching everyone else. A furniture maker still emails certificates. A service agency still answers the same onboarding questionnaire every quarter. The trust-center lesson stayed stuck in software, and it didn't need to.

What the SaaS world figured out

Three learnings from a decade of SaaS trust centers:

  1. Buyers self-serve if you let them. When the evidence is public and verifiable, the buyer checks it themselves and the deal moves. When it isn't, every check becomes an email that waits on you.
  2. One address beats many attachments. A single page with everything current beats fifty PDFs of unknown vintage.
  3. Staleness is fatal. A trust center that shows an expired certificate is worse than no trust center. Living documents — updated, dated, versioned — are the whole point.

None of that is software-specific. It applies to a chair, a chemical, a kitchen or a consultancy.

What a Trust Hex holds

A Trust Hex is that same structure applied to anything a business sells. Three layers:

  • Product pages. Each product carries its compliance — declarations, certificates, test references, sustainability metrics — on a live page with a permanent URL and QR code. The product trust center guide covers this layer.
  • Company documents. GDPR records, terms, accessibility statements, insurance summaries, modern slavery statements. The things every company has and almost no company publishes where a buyer can check them.
  • Service credentials. If you sell services, your compliance stack lives at company level: ISO 27001, NIS2 alignment, AI Act posture, DPAs. We wrote the SOC 2 vs CE marking comparison about exactly this split.

One verifiable address, everything a buyer, auditor, customs officer or lender might ask for — current by design.

Why buyers like it

Procurement teams are drowning in documentation. A buyer who can verify your certificates with a scan instead of an email chain is a buyer who moves faster — and who remembers which supplier was easy to work with. The same logic that made SaaS trust centers a sales tool makes a Trust Hex a sales tool for physical products and services. We've written before about what it costs when you don't have one.

How Sustalium Helps You Build a Trust Hex

  • Product, company and service layers — every asset in one verifiable structure, each with its own permanent URL.
  • Living documents — updates, versions and expiry dates stay current; nothing goes stale quietly.
  • One link to share everywhere — your website footer, invoices, listings and onboarding forms all point to the same address.

One Address for Everything You Comply With

Build your Trust Hex once, link it everywhere, and let buyers verify instead of emailing. Start with a free draft: no card needed, publish the verifiable version when you are ready.

[See the Trust Hex →](/trust-hex/){ .md-button .md-button--primary }

Frequently Asked Questions

Is a Trust Hex the same as a SaaS trust center?

Same idea, wider scope. SaaS trust centers hold security reports for software buyers; a Trust Hex holds product compliance, company documents and service credentials for any business.

Do I need separate pages for products and company documents?

Yes — different audiences, different evidence. A customs officer doesn't need your SOC 2 report, and a bank doesn't need your RoHS declaration. One structure, separate pages.

How does it stay current?

Documents are living: updates happen behind the same permanent URLs, expiry dates are tracked, and supplier or regulation changes flow into the pages they affect.



Last updated: September 2, 2026

Global Digital Trust & Compliance

Sustalium is the digital-first platform for managing complex business certificates and sustainability declarations across global supply chains.

Environment & ESG
  • Digital Product Passport (DPP)
  • Carbon & Water Footprint
  • Circularity & Reuse (ISO 14021)
  • De-Forestation Free
Product & Food Safety
  • FSMA 204 (FDA Traceability)
  • REACH & RoHS Compliance
  • PFAS-Free & VOC Declarations
  • Prop 65 & TSCA Title VI
Social & Ethical
  • ISO 26000 Responsibility
  • Modern Slavery Statements
  • UFLPA Forced Labor Traceability
  • Ethical Labor Declarations
Governance & Trade
  • Swiss Made & Origin Claims
  • GDPR & AI Ethics (EU AI Act)
  • CE Marking & UKCA Conformity
  • Bill S-211 (Canada) Reporting

Have questions about a specific standard?
Contact our compliance team at compliance@sustalium.com