← Back to news 17.07.2026

Security you can show

Every B2B deal now starts with a security questionnaire, and half the questions are always the same. Still, someone answers them by hand every time. Why the questionnaire flood will not go away, why a static security PDF is no answer, and how a trust center handles half the due diligence proactively.

Every B2B deal now starts with a security questionnaire. Which certifications? How about data protection and policies? Which subcontractors process data? Half the questions are the same from customer to customer, and still someone answers them by hand every time, often under pressure, because the deal hangs on the questionnaire.

The questionnaire flood has a good reason

The flood is annoying, but it is not unjustified: your customers have to vet their supply chain, NIS2 and DORA demand it explicitly, ISO 27001 likewise. Seen from the other side, it is exactly the diligence you want from your own suppliers. The consequence is just inconvenient: these requests will not decrease but increase. Whoever answers them purely reactively lets sales and the security team compete for the same hours.

Show it instead of claiming it anew each time

The alternative is a trust center: a public page that answers your security and compliance posture proactively, before the questionnaire arrives. The source is what matters. A glossy PDF from last year proves nothing; it ages from the day of its release. The page only becomes credible when it is fed from the systems where the work actually happens, showing the state of today instead of the state of the last revision.

How isidaten feeds the trust center

The trust center in isidaten is a public posture page that pulls live data from the other modules: the state of ISO 27001 and GDPR, policies, audits and awareness training. On top comes system status from uptime monitoring: curated monitors show label, status and availability, never the internal addresses behind them. The page is shared via link, QR code or embedded as an iframe on your own website. The subprocessor register answers the question that appears in practically every questionnaire. And for everything that does not belong in public, there is tiered depth: prospects file an access request and see confidential content only after approval, NDA-gated if you wish. The page handles half the due diligence before a human has to answer.

More is shown on the trust center module page. And if you want to lower your questionnaire load, talk to us.

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.