Trust Center Overview
Last updated: March 21, 2026
Overview
The Trust Center in Mycroft is a dedicated place to share your organization’s security, and compliance information with customers and prospects. It includes a public-facing webpage, an editor and a tab for managing visitor access.
Public Trust Center page
A page that anyone can open (when the Trust Center is live). It contains:
Overview – Title, description, and links (e.g. website, contact email, privacy policy).
Compliance – Frameworks and status (e.g. Compliant, In progress).
Trusted by – Customer logos or names.
Resource library – Documents grouped as Compliance, Security, or Policies. Some resources are only visible or downloadable after access is granted.
Controls – Security controls grouped by category (e.g. Infrastructure security, Data and privacy).
Subprocessors – List of subprocessors with name and location.
Frequently asked questions (FAQs) – Customizable Q&A.
Trust Center editor
Where your team edits the content that appears on the public page: overview, compliance frameworks, trusted-by logos, resources, controls, subprocessors, and FAQs. You can also change styling (e.g. fonts, background) and switch the Trust Center live or offline.
Access management
Visitors can request access to view and download protected resources. Your team reviews Requests and can Grant access to specific people. History shows past requests and grants. Access can be time-limited when granting. Permissions to approve or reject access requests can be configure in the Settings menu.
Who sees what
Public visitors see the live Trust Center page. They can browse open content (e.g. overview, compliance, controls, subprocessors, FAQs). To view or download items in the Resource library that require access, they must Request access and then use the link sent to their email after a member of your organization grants access.
Your organization uses the Mycroft dashboard to edit the Trust Center, manage access requests, and grant or revoke access. Org settings > Trust center is where you configure the NDA for access requests, who receives those requests, and the Trust Center website domain.
Making the Trust Center live or offline
From the Trust Center Editor, use the visibility control to Make live or Take offline. When the Trust Center is live, the public page is reachable at trust.mycroft.io/[your_org_slug] or default URL. When it is offline, the page is not available publicly. Only users who already have granted access may still have limited access until that grant expires or is revoked.
Trust Center Control Categories
Controls on the Trust Center are security and compliance controls that describe how your organization safeguards data and manages risk. They are grouped into control categories so visitors can browse by topic.
How controls appear
On the public Trust Center page, each category is shown as an expandable section. The section header shows the category name and the number of controls. Expanding a section lists the individual control names. Your team adds and organizes controls in the Trust Center Editor in the Controls section.
Adding Policies and Documents (Resource Library)
The Trust Center Resource library shows documents in three categories: Compliance, Security, and Policies. Policy documents (e.g. internal policies, terms) are added under the Policies category.
Where to add Trust Center Resources
In the Mycroft dashboard, open Trust Center (or Trust Center V2) and go to the Editor.
Scroll to the Resource library section.
Click Edit or the action that opens the resource selection/editing modal.
Select the category (Compliance, Security, Policies)
Add a new resource:
Enter a title and optional description.
Upload the policy file (supported format, e.g. PDF).
Save.
The new document then appears in the Resource library under Resource Library on the public Trust Center page (when the Trust Center is live). All visitors must request access and acknowledge an NDA in order to view or download the document.
Important
Documents in Mycroft are not automatically added to the Trust Center (e.g. policy lifecycle or approval workflows). We’ve done this to prevent accidental leaking of sensitive information to outside parties. If a policy is updated or a new document is added, you must manually add that document to Trust Center.
Adding a Custom NDA for Access Requests
When visitors Request access to the Trust Center, they are required to agree to a Non-Disclosure Agreement (NDA). You can use the default NDA provided by Mycroft or upload your own.
Where to configure the NDA
In the Mycroft dashboard, go to Org settings.
Open the Trust center tab.
Find the section NDA required to request access.
Options
On / Off
Turn On to require NDA agreement before submitting an access request. Turn Off to not require an NDA.
Use Mycroft default NDA
When NDA is On, choose this option to use the standard Mycroft NDA. Requesters will see a link to that NDA and must agree before submitting.
Use custom uploaded NDA
When NDA is On, choose this option to use your own NDA document. Use Upload file to upload a PDF. The file is stored and linked from the access request form. Requesters must read and agree to your NDA before submitting.
After changing the NDA setting or uploading a new file, click Save. New access requests will use the selected NDA. Existing requests are not changed.
Important
Only one NDA is active at a time: either the Mycroft default or your custom uploaded file. Uploading a new custom NDA replaces the previous custom file for that organization.
Customizing Your Domain
You can choose how the public Trust Center page is reached: using Mycroft’s default domain with a slug, or your own custom domain.
Where to set the domain
In the Mycroft dashboard, go to Org settings.
Open the Trust center tab.
Find the section Trust center website domain.
Options
Use default domain with slug
The Trust Center is available at a Mycroft default URL that includes a slug (e.g. a short identifier for your organization). Enter the Slug value in the field. The resulting URL uses the default Trust Center domain and includes your slug (e.g.
https://trust.example.com/your-slug, depending on your deployment). Use this option if you do not need a branded domain.Use custom domain
The Trust Center is served from your own domain (e.g.
trust.yourdomain.com). Enter the full domain in the Custom domain field (e.g.trust.yourdomain.com). Your DNS must be configured so that this host points to the correct Mycroft or hosting endpoint as required by your deployment.
After choosing an option and entering the slug or custom domain, click Save. The public Trust Center page will be reachable at the configured URL when the Trust Center is live.
Note
If you use a custom domain, ensure SSL and DNS are set up correctly for that host so visitors get a valid, secure connection.
Approving access requests via Slack (Slackbot)
If you connect Mycroft to Slack, Mycroft can send access request notifications to your Slack direct messages. You can approve, temporarily approve, or deny requests directly from those notifications.
<aside> ⚠
You must have connected Slack in your Mycroft dashboard at app.mycroft.io/integrations. If Slack was connected before Feb 20th, 2025, you may need to disconnect and reconnect the integration. No data is lost by reconnecting.
</aside>
Set up the Slackbot
In any Slack channel, run the Mycroft
/connectcommand.Follow the prompt to connect your Mycroft account to your Slack account.
In the Mycroft dashboard, go to Trust Center Settings: app.mycroft.io/org-settings/trust-center.
Under Access request recipients, ensure you are listed as a recipient.
What happens next
You will receive notifications by email and Slack DMs whenever someone requests access to your Trust Center.
From the Slack notification, you can approve, temporarily approve, or deny access.
Troubleshooting Trust Center Access Issues
This section helps when someone cannot access the Trust Center page or cannot view or download resources after requesting access.
The Trust Center page does not load or returns “not found”
Check that the Trust Center is live. In the dashboard, open the Trust Center Editor. If the status is offline, the public page will not be available. Use Make live to publish it.
Check the URL. Confirm the visitor is using the correct URL: either the default URL with your slug (from Org settings > Trust center > Trust center website domain) or your custom domain if configured. Typos or an old bookmark can lead to a “not found” or wrong page.
Check the organization. If your instance supports multiple organizations, ensure the URL matches the organization that owns the Trust Center (e.g. correct slug or domain for that org).
A visitor requested access but cannot view or download resources
They must use the link from the grant email. After you Grant access from the dashboard (Trust Center > Access requests > Grant access), the recipient receives an email with a link. That link includes a grant parameter. They should open the Trust Center from that link (or the link will store the grant in the browser). If they go to the Trust Center URL without that grant, they will not have access to protected resources.
Grant may have expired. If you set an expiration date when granting access, the grant stops working after that date. They will need to request access again and be granted a new link.
Grant may have been revoked. If access was revoked from the History (or equivalent) in the dashboard, the old link will no longer work. They must submit a new request and be granted again.
“Reclaim access” for visitors who already had access
If a visitor had access before (e.g. they lost the grant link or switched devices), they can use Reclaim access on the Trust Center page. They enter the same email address that was used when access was granted. If that email has an active grant, they receive a new link to regain access. If they do not receive a link, they may need to request access again from the Request access flow so your team can approve and grant again.
Recipients not receiving access request notifications
Check access request recipients. In Org settings > Trust center, the Access request recipients list defines who receives notifications for new access requests. Ensure the right teammates are added as Recipients and that their email addresses are correct.
Check spam/junk. Ask recipients to check spam or junk folders and to allowlist the sender or domain used by Mycroft for these emails.
NDA or request form issues
If the Request access form requires NDA agreement but the NDA link is broken, go to Org settings > Trust center and confirm NDA required is On and either Use Mycroft default NDA is selected or Use custom uploaded NDA has a valid file uploaded. Re-save if you made changes.
If requesters report that the form does not submit, ensure they have filled all required fields (e.g. first name, last name, work email, company, reason) and, when applicable, have checked the NDA agreement. Clearing cache or trying another browser can help rule out client-side issues.