Skip to content
The Clean OpinionPowered byAlpha Secure LLP
Tools/Trust · Free · About 2 min

Trust Page Grader

Enterprise reviewers read a trust page with a checklist in their head. This grades yours against that checklist, in plain English, and points out where the copy is ahead of the evidence.

Runs in your browser. Nothing you type is sent anywhere unless you choose to export it. Privacy

Optional, for the report header only. The page is not fetched; paste the text below.
Select all on the page and paste. HTML is fine; it gets stripped. Nothing leaves your browser.
Paste the page and answer both questions to run the grade.
Your grade appears here: a score out of 100, the checklist items present and missing, the strongest signals on the page, and any claim worth a second look before a buyer sees it.

What should a trust page include?

Ten things, in roughly the order enterprise reviewers look for them: an audit report, a trust page or security overview, a privacy policy, a subprocessor list, a way to request evidence, a security contact, a status page, a vulnerability disclosure path, an incident response process, and data retention and deletion.

How this calculator works

You paste the text of your trust or security page and it is graded locally, in your own browser. The URL field is a label for the report header only — no page is ever fetched, by your browser or by a server — so a URL on its own grades nothing.

Ten completeness checks run over the pasted text, each owning a list of keyword patterns, fifty-five in total. A check is credited the first time any one of its patterns matches somewhere that is not negated. The ten weights sum to a hundred: an audit report is worth eighteen, a trust page or security overview twelve, then privacy policy, subprocessor list and evidence process at ten each, and security contact, status page, vulnerability disclosure, incident response and data retention at eight each.

Negation is honoured. A match is discarded when a negating word appears within the ten words before it, so a page saying it has no status page is not credited with one. Where a check's only matches were negated, the page's own sentence is quoted back as an admission rather than counted as present.

Scoring is a plain sum of the weights credited — no partial credit, no penalties, and no interaction between checks. Eighty-five or more is a complete page, seventy a mostly complete one, fifty partial, thirty thin, and under thirty is not yet a trust page. The two questions about who your buyers are steer the urgency and the notes; they never move the score.

Separately, thirteen phrase rules flag claims that tend to invite harder questions than they answer: absolute language, framework names used as though they were certifications, and promises of security that cannot be evidenced. These are wording flags, not findings. The grader cannot tell whether a claim is true, and it will flag an accurate statement that is merely imprecisely worded. They never affect the score.

What the grade measures is the page, not the company. A perfect hundred means ten families of keywords appeared in the text pasted, and it is fully reachable by a page that simply says it has all ten things. It is not an audit, not an assessment of controls, and says nothing about whether a company is secure.

A worked example

A B2B SaaS trust page that names a SOC 2 report and an NDA route to it, covers privacy, retention and a security contact, and carries some marketing language about encryption.

What goes in
Pasted page
12 lines of a typical trust page — SOC 2, annual third-party audit, AES-256, privacy policy, 30-day deletion, a security@ address, evidence under NDA
Sells to enterprise
Yes
Customers ask for security documents
Yes
What comes back
Score
74 of 100 — band B, mostly there
Present
7 of 10
Missing
Subprocessor list, status page, incident response process
Claims flagged
3 — “100% secure”, “military-grade”, “SOC 2 certified”
Urgency
Low

Eighteen for the audit report, twelve for the security page, ten each for privacy, retention and the evidence process, and eight each for the security contact and vulnerability disclosure adds to seventy-four. Two things are worth noticing. A single security@ address credits both the security contact and the vulnerability disclosure check — sixteen points from one line. And urgency came back low on a page carrying three flagged claims, because urgency keys off the report and the score, and ignores the claim flags entirely.

Common questions

Can I just enter my URL?
No. The page is never fetched, and the URL field only labels the report header. Select the text of your trust page and paste it in — HTML is fine, and the markup gets stripped before anything is graded.
Does a high score mean my company is secure?
No. It means ten families of keywords appeared in the text you pasted. A page can reach a hundred by claiming all ten things, and the grader has no way to check that any referenced document exists, is current, or covers what it says it covers.
Where do the weights come from?
They are the editorial judgement of the auditors who built the tool about what enterprise reviewers look for first. They are not derived from a standard, a framework, or a survey of trust pages, and they are published so you can disagree with them.
What does a flagged claim mean?
That a phrase tends to invite harder questions than it answers — never that it is false. The grader cannot assess truth, and it will flag an accurate statement that is only imprecisely worded, such as writing “ISO 27001 compliant” when you actually hold the certificate.
Does my pasted page get sent anywhere?
The grading runs entirely in your browser and the paste never leaves it. If you request the PDF, the result is sent so the report can be emailed — and the result contains short excerpts of your page, including the flagged phrases.
Is the ten-item list everything a buyer will ask about?
No. It is a deliberate shortlist of what this grader checks. Encryption, access control, business continuity, penetration-test cadence and security training are questionnaire staples that are not checked here at all.

This tool grades the completeness of a public trust or security page against a fixed checklist. It is not a security assessment, not an audit opinion, and says nothing about whether a company is secure. A high score means the page answers the questions buyers ask first; it does not mean the controls behind it have been tested. Audits and attestations are performed by Alpha Secure LLP, a licensed CPA firm. Disclosure.