

Trust Exchange users on the paid tier can now publish their subprocessor list directly on their Trust Center. Subprocessors are the third party vendors that handle customer data on their behalf, such as cloud hosting or payment processing. Prospects and customers can see this list without having to request it, which resolves a common compliance question early in every security review.
General availability for new Trust Exchange and Vendor Risk APIs
Customers can now build against new stable, supported endpoints across Trust Exchange and Vendor Risk, as a set of public APIs moves to general availability. In Vendor Risk, the new APIs cover retrieving vendor classic assessment details, lists, and versions, adding and updating vendor contacts, adding questionnaire comments, and updating questionnaire status. Trust Exchange NDA and Trust Center access management APIs are also generally available, giving users a stable, supported interface to automate their NDA workflows and access management programmatically.
NCA compliance badges on the Trust Center
Trust Exchange customers can now display National Cybersecurity Authority (NCA) compliance badges on their Trust Center for NCA ECC (Essential Cybersecurity Controls) and NCA DCC (Data Cybersecurity Controls). Visitors see which frameworks an organization meets without needing to request them. This matters to buyers in Saudi Arabia, where both frameworks are mandatory for government entities and critical infrastructure operators.






