Trust center

Public trust page

What visitors see on your published trust page and how requests reach you.

RolesViewerEditorAdminRoute/trust/[trust-id]Shown toCompliance organizations

What it is

The public trust page is the visitor-facing result of the builder: a single page on your custom domain that shows your compliance frameworks, the controls you operate, approved policies as downloadable resources, your subprocessors, and a way to contact you or request a certificate. It is served as a static snapshot from Noru's infrastructure, so it stays up regardless of the app, and it changes only when you publish.

Where to find it

Trust CenterBuilderexternal-link icon

Two addresses serve the same content. Your custom domain (for example trust.example.com) is the public one. /trust/[trust-id] in the app is the preview: while the page is unpublished only members of the owning organization can open it, and everyone else gets a 404. Once published, both render the same snapshot.

A published trust page with the hero, compliance cards, resources, and subprocessors sectionsA published trust page with the hero, compliance cards, resources, and subprocessors sections
The compliance cards are the centrepiece; each carries a status pill and the audit facts a reviewer wants.

What visitors see

SectionContentsWhere it comes from
HeaderLogo, section navigation, and a Contact button that opens a mail draft to your contact emailBranding tab
HeroIntroduction title, tagline, two paragraphs, custom buttonsContent tab
ComplianceOne card per framework: logo, status pill, description, then Auditor, Valid through, and Certificate number when setSections tab and framework settings
ControlsThe controls you operate, groupedYour control set
ResourcesApproved policies as downloadsContent tab; policy approval
SubprocessorsThird-party processorsVendor records
ContactYour contact detailsBranding tab
Footer"Powered by" NoruFixed

A framework whose Certificate file is attached in the builder shows a Request certificate button under its card. Everything else on the page is open.

Key actions

Request a certificate (as a visitor)

Click Request certificate under the framework card.
Enter a Name and Email, then click Send request; Cancel closes the form.
The card replaces the form with "Request sent. The team will review it before sharing the certificate."

The request arrives in Trust center requests, where your team approves or rejects it. If a visitor reports an error, the form shows "Unable to submit request"; the usual cause is a missing name or email, since Send request stays disabled until both are filled.

Check what is live

Open your custom domain in a private window. If the page still shows the old version a minute after publishing, the browser or a corporate proxy is caching it; Noru clears its own edge cache on every publish.

Statuses and fields

Status pills on compliance cards are resolved from the framework's status and the Verification status you set in the builder (Verified, Compliant, In Progress, Expired). Valid through prints only when a validity date is set and parses; Certificate prints the number only. Dark mode follows the visitor's system setting when Allow dark mode is on and uses the Dark mode logo (optional) if you uploaded one.

Tips and gotchas

The preview at /trust/[trust-id] is built live from the saved draft, so it can differ from the published page. Treat it as "what the next publish will show", not "what visitors see now".

Keep the contact email a shared mailbox. The Contact button and the certificate flow both depend on someone reading it.

What Noru does not do

Noru does not gate the page behind a login, an NDA, or a per-visitor approval; the only gated item is the certificate file. It does not show live control status: the page is a snapshot from the last publish. It does not collect analytics on visitors, and it does not send the requester anything until your team approves.

Last updated on