Trust Center vs Compliance Center — which surface serves which audience
Devotel Orbit ships two compliance surfaces that serve different audiences. Sales, procurement, and operations teams conflate them; support answers differ by role. This page draws the line between the public Trust Center and the in-product Compliance Center so you always link the right audience to the right surface.The two surfaces
The split is simple: the Trust Center is what Devotel publishes about the platform. The Compliance Center is what you configure inside your workspace.
When to link to each
Trust Center — the procurement surface
Link the Trust Center when a buyer, vendor-review team, or security assessor asks for evidence about the platform itself:- The subprocessor register and data-residency disclosure — open to anyone, no login
- SOC 2 control mappings, ISO 27001 certification posture, and the gated-evidence request form — the Trust Center evidence pack sequences the full procurement path
- The counter-signed DPA, answered security questionnaires (CAIQ, SIG-Lite), and pentest summaries — issued under NDA through the Request the trust pack form at the bottom of the Trust Center
Compliance Center — the workspace configuration surface
Link Settings → Compliance when a tenant owner or admin needs to configure their own posture:- Accept the DPA (GDPR Article 28 record)
- Execute the BAA (HIPAA business associate agreement)
- Toggle send gates, quiet hours, DNC/RND scrubbing, and fraud caps
- Generate evidence binders, audit exports, and SIEM-sink outputs
- Set HIPAA mode, PHI audiences, and the Security Officer contact
The two most-asked URLs from devotel/sales tickets
Sales and procurement ask two things more than any other compliance URL:1. “Where do I download the DPA?”
The public-facing DPA download flow starts atGET /api/v1/compliance/dpa/template. No tenant login needed — the endpoint serves the canonical DPA template to anyone. The buyer previews, reviews, or files the template as part of procurement intake. This is the processor-provided artifact, identical for every workspace.
The tenant-side DPA acceptance (POST /api/v1/compliance/dpa/accept) happens inside the Compliance Center — the tenant owner types their legal name to sign. That acceptance is a contractual record for your organization; it does not gate any product capability. The two flows are deliberately separate: the buyer reads the template; the tenant owner accepts it.
2. “Where do I execute the BAA?”
The BAA is a tenant-executed agreement under Settings → Compliance → HIPAA. It is not downloadable from the public Trust Center — only a workspace with HIPAA enabled can execute it. The sequence is:- Enable HIPAA mode under Settings → Compliance → HIPAA
- Review and execute the BAA (typed e-signature, same pattern as the DPA)
- The executed copy is stored under your organization; the
baa_signed_atdate appears in generated evidence binders
How tenant-owned toggles map onto Trust Center claims
The Trust Center states platform-level posture — encryption posture, subprocessor register, SOC 2 control mappings. The Compliance Center controls your workspace-level posture — send gates, quiet hours, HIPAA mode, the BAA. The two surfaces intersect at the evidence binder. When a buyer asks whether a specific control is in place, the answer depends on whose control it is:
The binder is the boundary: a generated evidence pack stitches platform-fixed rows (from the Trust Center’s claims) and workspace-derived rows (from your Compliance Center settings) into a single artifact. The evidence pack page explains how.
Route support questions to the right surface
When a support ticket conflates the two:- “Where is the DPA?” — link the DPA page; distinguish the public template download from the tenant acceptance step
- “Can I send this buyer our SOC 2?” — link the Trust Center for the open evidence, and the evidence binder for per-framework generation
- “Where do I turn on HIPAA?” — link the HIPAA onboarding guide; the toggle lives under Settings → Compliance, not the public Trust Center
- “The buyer wants our BAA” — route to BAA; execute it inside the Compliance Center first, then generate the HIPAA evidence binder
Related
- Trust Center evidence pack — the procurement sequence: framework binders, the three-API-call generation loop, and the forwarding checklist
- Your tenant compliance posture — the toggle map: which controls are yours to switch and where each lives
- Data Processing Agreement — the DPA lifecycle: preview, accept, archive, and version-update
- BAA — the HIPAA business associate agreement lifecycle
- Evidence binder — the generator: framework scope, formats, tamper flags, and worked examples
- Compliance FAQ — routes a first question to the page that owns it