Skip to main content

Trust Center vs Compliance Center — which surface serves which audience

Devotel Orbit ships two compliance surfaces that serve different audiences. Sales, procurement, and operations teams conflate them; support answers differ by role. This page draws the line between the public Trust Center and the in-product Compliance Center so you always link the right audience to the right surface.
This page describes Orbit’s platform controls. It is not legal advice. Which surface a buyer or auditor needs depends on their role, your contracts, and the framework they are assessing against. Confirm the specifics with qualified counsel.

The two surfaces

The split is simple: the Trust Center is what Devotel publishes about the platform. The Compliance Center is what you configure inside your workspace.

Trust Center — the procurement surface

Link the Trust Center when a buyer, vendor-review team, or security assessor asks for evidence about the platform itself:
  • The subprocessor register and data-residency disclosure — open to anyone, no login
  • SOC 2 control mappings, ISO 27001 certification posture, and the gated-evidence request form — the Trust Center evidence pack sequences the full procurement path
  • The counter-signed DPA, answered security questionnaires (CAIQ, SIG-Lite), and pentest summaries — issued under NDA through the Request the trust pack form at the bottom of the Trust Center
These are artifacts Devotel signs. No tenant login is involved; the public page carries open evidence, and the gated section processes inbound access requests from the trust desk.

Compliance Center — the workspace configuration surface

Link Settings → Compliance when a tenant owner or admin needs to configure their own posture:
  • Accept the DPA (GDPR Article 28 record)
  • Execute the BAA (HIPAA business associate agreement)
  • Toggle send gates, quiet hours, DNC/RND scrubbing, and fraud caps
  • Generate evidence binders, audit exports, and SIEM-sink outputs
  • Set HIPAA mode, PHI audiences, and the Security Officer contact
These are controls your organization owns. Devotel enforces what you set; it does not pick a posture for you. Every toggle under Settings → Compliance is documented in the posture overview.

The two most-asked URLs from devotel/sales tickets

Sales and procurement ask two things more than any other compliance URL:

1. “Where do I download the DPA?”

The public-facing DPA download flow starts at GET /api/v1/compliance/dpa/template. No tenant login needed — the endpoint serves the canonical DPA template to anyone. The buyer previews, reviews, or files the template as part of procurement intake. This is the processor-provided artifact, identical for every workspace. The tenant-side DPA acceptance (POST /api/v1/compliance/dpa/accept) happens inside the Compliance Center — the tenant owner types their legal name to sign. That acceptance is a contractual record for your organization; it does not gate any product capability. The two flows are deliberately separate: the buyer reads the template; the tenant owner accepts it.

2. “Where do I execute the BAA?”

The BAA is a tenant-executed agreement under Settings → Compliance → HIPAA. It is not downloadable from the public Trust Center — only a workspace with HIPAA enabled can execute it. The sequence is:
  1. Enable HIPAA mode under Settings → Compliance → HIPAA
  2. Review and execute the BAA (typed e-signature, same pattern as the DPA)
  3. The executed copy is stored under your organization; the baa_signed_at date appears in generated evidence binders
If a buyer asks for a pre-signed BAA before you have executed it inside your workspace, redirect them to the evidence binder HIPAA flow — the BAA execution date appears in your binder, and the absence of a date answers the question honestly.

How tenant-owned toggles map onto Trust Center claims

The Trust Center states platform-level posture — encryption posture, subprocessor register, SOC 2 control mappings. The Compliance Center controls your workspace-level posture — send gates, quiet hours, HIPAA mode, the BAA. The two surfaces intersect at the evidence binder. When a buyer asks whether a specific control is in place, the answer depends on whose control it is: The binder is the boundary: a generated evidence pack stitches platform-fixed rows (from the Trust Center’s claims) and workspace-derived rows (from your Compliance Center settings) into a single artifact. The evidence pack page explains how.

Route support questions to the right surface

When a support ticket conflates the two:
  • “Where is the DPA?” — link the DPA page; distinguish the public template download from the tenant acceptance step
  • “Can I send this buyer our SOC 2?” — link the Trust Center for the open evidence, and the evidence binder for per-framework generation
  • “Where do I turn on HIPAA?” — link the HIPAA onboarding guide; the toggle lives under Settings → Compliance, not the public Trust Center
  • “The buyer wants our BAA” — route to BAA; execute it inside the Compliance Center first, then generate the HIPAA evidence binder