Pricing & positioning
Why DeliverTrust over a cheaper trust portal like SimpleTrustPortal?
SimpleTrustPortal is cheaper ($16-20/month) but it gates a flat list of PDFs behind an NDA - no Overview, Controls, Subprocessors, FAQ, or custom pages.
See the full comparisonWhy DeliverTrust over a compliance platform like Vanta or Drata?
Vanta and Drata are compliance-automation platforms - they run your whole compliance program (evidence collection, continuous monitoring, audits) and price like it: neither publishes a rate card, and buyer reports commonly put contracts at $5,000/year and up. If all you need is a trust page, that's a lot of platform to buy. DeliverTrust is a trust page, not a compliance platform: $50/month flat, publicly listed, no sales call. You keep your own compliance program either way - DeliverTrust just publishes what it produces.
See the full comparisonSecurity & trust
Do you certify our security posture?
No. DeliverTrust is the publication layer. You bring your own SOC 2 report, policies, and claims; we host them, gate them behind an NDA when you want, and notify your team when someone requests access. We don't audit, certify, or warrant the accuracy of what you publish.
Do you watermark downloaded documents?
Yes. Every gated PDF is watermarked on download with the viewer's email and a UTC timestamp, so a leaked copy traces back to who downloaded it. Each download is also written to your audit log.
How is my data isolated from other customers?
Each tenant gets its own Cloud Storage bucket, encrypted with its own dedicated Cloud KMS key - not one shared bucket with a folder per customer. Documents are never co-mingled, and there's no shared staging or scratch surface anywhere in the upload path. Everything is hosted in the US (Google Cloud), and deleting a tenant crypto-shreds its documents by destroying that tenant's key.
Access & workflow
Can we block prospects from signing up with personal emails?
Yes. The workflow editor has a 'block generic email domains' toggle with a default list (gmail, yahoo, hotmail, outlook, icloud, proton, etc.) that you can edit. Visitors using those domains see a friendly 'work email required' error.
What about manual review?
Per-document toggle. When a flagged document is requested, your workflow's manual-review step fires instead of auto-grant. Reviewers get a notification with one-click approve/reject magic-links. The requester gets a templated email with either the access link or a polite rejection. Invite teammates and give each a role - Administrator, Editor, Viewer, or Approver - and Approvers can review that queue without edit access to the rest of your Trust Center.
How do notifications work?
Per workflow step, you pick which channels fire: email to one or more admin addresses, a Slack incoming-webhook URL, or any generic JSON webhook (Zapier, n8n, your own service). Each notification is rendered from a templated message you can customize in the workflow editor.
Platform
Can we use our own domain?
Yes. CNAME `trust.yourcompany.com` to `cname.delivertrust.io` and your Trust Page serves at your own domain with a managed TLS certificate. DeliverTrust checks the domain every ten minutes and emails your Administrators if it stops working, and again when it is back.
Want to go deeper? Read our Trust Center guides.