Public trust page
What visitors see on your published trust page and how requests reach you.
What it is
The public trust page is the visitor-facing result of the builder: a single page on your custom domain that shows your compliance frameworks, the controls you operate, approved policies as downloadable resources, your subprocessors, and a way to contact you or request a certificate. It is served as a static snapshot from Noru's infrastructure, so it stays up regardless of the app, and it changes only when you publish.
Where to find it
Trust CenterBuilderexternal-link iconTwo addresses serve the same content. Your custom domain (for example
trust.example.com) is the public one. /trust/[trust-id] in the app is the
preview: while the page is unpublished only members of the owning
organization can open it, and everyone else gets a 404. Once published, both
render the same snapshot.


What visitors see
| Section | Contents | Where it comes from |
|---|---|---|
| Header | Logo, section navigation, and a Contact button that opens a mail draft to your contact email | Branding tab |
| Hero | Introduction title, tagline, two paragraphs, custom buttons | Content tab |
| Compliance | One card per framework: logo, status pill, description, then Auditor, Valid through, and Certificate number when set | Sections tab and framework settings |
| Controls | The controls you operate, grouped | Your control set |
| Resources | Approved policies as downloads | Content tab; policy approval |
| Subprocessors | Third-party processors | Vendor records |
| Contact | Your contact details | Branding tab |
| Footer | "Powered by" Noru | Fixed |
A framework whose Certificate file is attached in the builder shows a Request certificate button under its card. Everything else on the page is open.
Key actions
Request a certificate (as a visitor)
The request arrives in Trust center requests, where your team approves or rejects it. If a visitor reports an error, the form shows "Unable to submit request"; the usual cause is a missing name or email, since Send request stays disabled until both are filled.
Check what is live
Open your custom domain in a private window. If the page still shows the old version a minute after publishing, the browser or a corporate proxy is caching it; Noru clears its own edge cache on every publish.
Statuses and fields
Status pills on compliance cards are resolved from the framework's status and the Verification status you set in the builder (Verified, Compliant, In Progress, Expired). Valid through prints only when a validity date is set and parses; Certificate prints the number only. Dark mode follows the visitor's system setting when Allow dark mode is on and uses the Dark mode logo (optional) if you uploaded one.
Tips and gotchas
The preview at /trust/[trust-id] is built live from the saved draft, so it
can differ from the published page. Treat it as "what the next publish will
show", not "what visitors see now".
Keep the contact email a shared mailbox. The Contact button and the certificate flow both depend on someone reading it.
What Noru does not do
Noru does not gate the page behind a login, an NDA, or a per-visitor approval; the only gated item is the certificate file. It does not show live control status: the page is a snapshot from the last publish. It does not collect analytics on visitors, and it does not send the requester anything until your team approves.
Related
Last updated on