React Trust Center
The page a security reviewer asks for on day one of procurement. Publishing it properly converts a two-week questionnaire cycle into a link you paste once.
Trust & security
Everything a security review needs, without a questionnaire.
- Uptime commitment
- 99.95%
- Critical response
- 1 hr
- RTO
- 4 hrs
- RPO
- 15 min
monthly, excl. maintenance
24/7 for P1
tested quarterly
continuous replication
- Request
SOC 2 Type II report
Security and availability criteria, 12-month observation window.
Updated 2026-05-14
- Download
Penetration test summary
Independent assessment by Vector Test Labs. Full report under NDA.
Updated 2026-04-02
- Download
Information security policy
Access control, key management, incident response.
Updated 2026-06-30
- Download
Data processing addendum
GDPR Article 28 terms, standard contractual clauses.
Updated 2026-01-19
- Request
Business continuity plan
RTO/RPO targets and tested failover procedure.
Updated 2026-03-08
Reporting a vulnerability
Email security@example.com. We acknowledge within one business day and will not pursue good-faith researchers. Full disclosure policy.
Installation
Props
| Prop | Type | Description |
|---|---|---|
| documents | TrustDocument[] | { id, name, description?, updated?, gated?, href? } |
| subprocessors | Subprocessor[] | { name, purpose, location, personalData? } |
| sla | SlaCommitment[] | { label, value, detail? } |
| securityContact | { email, policyHref? } | Vulnerability disclosure — never omit |
| statusHref | string | Link to your status page |
Dates, gating, and the subprocessor table
Three details that separate a useful trust centre from a marketing page wearing one:
- Every document carries
updated. A policy with no date tells a reviewer nothing — they cannot distinguish "current" from "written once in 2021". This is the first thing an experienced assessor looks for. - Gated documents say so up front.
gatedrenders a Request action instead of Download. SOC 2 reports and full pen-test results legitimately sit behind an NDA; what loses trust is presenting them as downloads and then springing a form. - The subprocessor table names who touches personal data. Provider, purpose, location, and a personal-data flag are the exact columns a GDPR Article 28 review needs. Publishing the list is a controller obligation in practice, and keeping it current is what makes it worth anything.
Always publish a disclosure route
The vulnerability contact is the section not to skip. A researcher who cannot find where to report will either give up or disclose publicly, and neither outcome is one you want. State the acknowledgement window and commit in writing not to pursue good-faith research — that sentence is what makes people actually use the address.
New components every week
Get the week's new Kelvin UI components and templates in one short email. No spam, unsubscribe anytime.