React Trust Center

The page a security reviewer asks for on day one of procurement. Publishing it properly converts a two-week questionnaire cycle into a link you paste once.

Trust & security

Everything a security review needs, without a questionnaire.

System status
Uptime commitment
99.95%

monthly, excl. maintenance

Critical response
1 hr

24/7 for P1

RTO
4 hrs

tested quarterly

RPO
15 min

continuous replication

  • SOC 2 Type II report

    Security and availability criteria, 12-month observation window.

    Updated 2026-05-14

    Request
  • Penetration test summary

    Independent assessment by Vector Test Labs. Full report under NDA.

    Updated 2026-04-02

    Download
  • Information security policy

    Access control, key management, incident response.

    Updated 2026-06-30

    Download
  • Data processing addendum

    GDPR Article 28 terms, standard contractual clauses.

    Updated 2026-01-19

    Download
  • Business continuity plan

    RTO/RPO targets and tested failover procedure.

    Updated 2026-03-08

    Request

Reporting a vulnerability

Email security@example.com. We acknowledge within one business day and will not pursue good-faith researchers. Full disclosure policy.

Installation

npx shadcn@latest add "https://kelvinui.com/registry/trust-center.json"

Props

PropTypeDescription
documentsTrustDocument[]{ id, name, description?, updated?, gated?, href? }
subprocessorsSubprocessor[]{ name, purpose, location, personalData? }
slaSlaCommitment[]{ label, value, detail? }
securityContact{ email, policyHref? }Vulnerability disclosure — never omit
statusHrefstringLink to your status page

Dates, gating, and the subprocessor table

Three details that separate a useful trust centre from a marketing page wearing one:

  • Every document carries updated. A policy with no date tells a reviewer nothing — they cannot distinguish "current" from "written once in 2021". This is the first thing an experienced assessor looks for.
  • Gated documents say so up front. gated renders a Request action instead of Download. SOC 2 reports and full pen-test results legitimately sit behind an NDA; what loses trust is presenting them as downloads and then springing a form.
  • The subprocessor table names who touches personal data. Provider, purpose, location, and a personal-data flag are the exact columns a GDPR Article 28 review needs. Publishing the list is a controller obligation in practice, and keeping it current is what makes it worth anything.

Always publish a disclosure route

The vulnerability contact is the section not to skip. A researcher who cannot find where to report will either give up or disclose publicly, and neither outcome is one you want. State the acknowledgement window and commit in writing not to pursue good-faith research — that sentence is what makes people actually use the address.

New components every week

Get the week's new Kelvin UI components and templates in one short email. No spam, unsubscribe anytime.