> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust Center vs Compliance Center — which surface serves which audience

> The public Trust Center (marketing site /trust) vs the in-product Compliance Center (Settings → Compliance) — which audience each one serves, when to link to each, and how the tenant-owned toggles map onto the public procurement claims.

# Trust Center vs Compliance Center — which surface serves which audience

Devotel Orbit ships two compliance surfaces that serve different audiences. Sales, procurement, and operations teams conflate them; support answers differ by role. This page draws the line between the public Trust Center and the in-product Compliance Center so you always link the right audience to the right surface.

<Warning>
  This page describes Orbit's platform controls. It is **not legal
  advice.** Which surface a buyer or auditor needs depends on their role,
  your contracts, and the framework they are assessing against. Confirm
  the specifics with qualified counsel.
</Warning>

***

## The two surfaces

| Surface | Lives at | Audience | Owned by |
| - | - | - | - |
| **Trust Center** (public) | [orbit.devotel.io/trust](https://orbit.devotel.io/trust) | Procurement, security reviewers, prospects evaluating Orbit. Anyone with a browser. | Devotel — the platform operator |
| **Compliance Center** (in-product) | **Settings → Compliance** (dashboard, workspace-scoped) | Tenant owner, admin, compliance officer. Requires login. | Your organization — the tenant |

The split is simple: the Trust Center is what Devotel publishes about the platform. The Compliance Center is what you configure inside your workspace.

***

## When to link to each

### Trust Center — the procurement surface

Link the Trust Center when a **buyer, vendor-review team, or security assessor** asks for evidence about the platform itself:

* The subprocessor register and data-residency disclosure — open to anyone, no login
* SOC 2 control mappings, ISO 27001 certification posture, and the gated-evidence request form — the [Trust Center evidence pack](/compliance/trust-center-evidence-pack) sequences the full procurement path
* The counter-signed DPA, answered security questionnaires (CAIQ, SIG-Lite), and pentest summaries — issued under NDA through the **Request the trust pack** form at the bottom of the Trust Center

These are artifacts Devotel signs. No tenant login is involved; the public page carries open evidence, and the gated section processes inbound access requests from the trust desk.

### Compliance Center — the workspace configuration surface

Link **Settings → Compliance** when a **tenant owner or admin** needs to configure their own posture:

* Accept the [DPA](/compliance/data-processing-agreement) (GDPR Article 28 record)
* Execute the [BAA](/compliance/baa) (HIPAA business associate agreement)
* Toggle send gates, quiet hours, DNC/RND scrubbing, and fraud caps
* Generate evidence binders, audit exports, and SIEM-sink outputs
* Set HIPAA mode, PHI audiences, and the Security Officer contact

These are controls your organization owns. Devotel enforces what you set; it does not pick a posture for you. Every toggle under Settings → Compliance is documented in the [posture overview](/compliance/posture-overview).

***

## The two most-asked URLs from devotel/sales tickets

Sales and procurement ask two things more than any other compliance URL:

### 1. "Where do I download the DPA?"

The public-facing [DPA download flow](/compliance/data-processing-agreement#preview-and-download-the-dpa) starts at `GET /api/v1/compliance/dpa/template`. No tenant login needed — the endpoint serves the canonical DPA template to anyone. The buyer previews, reviews, or files the template as part of procurement intake. This is the **processor-provided artifact**, identical for every workspace.

The tenant-side DPA *acceptance* (`POST /api/v1/compliance/dpa/accept`) happens inside the Compliance Center — the tenant owner types their legal name to sign. That acceptance is a contractual record for your organization; it does not gate any product capability. The two flows are deliberately separate: the buyer reads the template; the tenant owner accepts it.

### 2. "Where do I execute the BAA?"

The BAA is a **tenant-executed agreement** under Settings → Compliance → HIPAA. It is not downloadable from the public Trust Center — only a workspace with HIPAA enabled can execute it. The sequence is:

1. Enable HIPAA mode under Settings → Compliance → HIPAA
2. Review and execute the BAA (typed e-signature, same pattern as the DPA)
3. The executed copy is stored under your organization; the `baa_signed_at` date appears in generated evidence binders

If a buyer asks for a pre-signed BAA before you have executed it inside your workspace, redirect them to the [evidence binder HIPAA flow](/compliance/trust-center-evidence-pack#per-framework-checklist--what-to-pre-build) — the BAA execution date appears in your binder, and the absence of a date answers the question honestly.

***

## How tenant-owned toggles map onto Trust Center claims

The Trust Center states platform-level posture — encryption posture, subprocessor register, SOC 2 control mappings. The Compliance Center controls your workspace-level posture — send gates, quiet hours, HIPAA mode, the BAA. The two surfaces intersect at the evidence binder.

When a buyer asks whether a specific control is in place, the answer depends on whose control it is:

| Control | Owned by | Where it lives |
| - | - | - |
| Encryption at rest (CMEK, server-side) | Devotel (platform) | Stated in the Trust Center; identical across every workspace. Read verbatim in any generated evidence binder. |
| Subprocessor register | Devotel (platform) | Published at `/trust`, open to anyone. Listed by the binder. |
| SOC 2 control mappings | Devotel (platform) | The mapping table is on the Trust Center; the binder generates per-framework packets from it. |
| DPA acceptance | Your organization (tenant) | Template from the public endpoint; acceptance under Settings → Compliance → DPA. |
| BAA execution | Your organization (tenant) | Settings → Compliance → HIPAA. The execution date appears in the HIPAA evidence binder. |
| Quiet hours and send gates | Your organization (tenant) | Settings → Compliance → Quiet hours / Send gates. |
| DNC and RND scrubs | Your organization (tenant) | Settings → Compliance. Enabled or not by you. |
| HIPAA mode and PHI audiences | Your organization (tenant) | Settings → Compliance → HIPAA. |

The binder is the boundary: a generated evidence pack stitches platform-fixed rows (from the Trust Center's claims) and workspace-derived rows (from your Compliance Center settings) into a single artifact. The [evidence pack page](/compliance/trust-center-evidence-pack) explains how.

***

## Route support questions to the right surface

When a support ticket conflates the two:

* "Where is the DPA?" — link the [DPA page](/compliance/data-processing-agreement); distinguish the public template download from the tenant acceptance step
* "Can I send this buyer our SOC 2?" — link the [Trust Center](https://orbit.devotel.io/trust) for the open evidence, and the [evidence binder](/compliance/evidence-binder) for per-framework generation
* "Where do I turn on HIPAA?" — link the [HIPAA onboarding guide](/guides/hipaa-onboarding); the toggle lives under Settings → Compliance, not the public Trust Center
* "The buyer wants our BAA" — route to [BAA](/compliance/baa); execute it inside the Compliance Center first, then generate the HIPAA evidence binder

***

## Related

* [Trust Center evidence pack](/compliance/trust-center-evidence-pack) — the procurement sequence: framework binders, the three-API-call generation loop, and the forwarding checklist
* [Your tenant compliance posture](/compliance/posture-overview) — the toggle map: which controls are yours to switch and where each lives
* [Data Processing Agreement](/compliance/data-processing-agreement) — the DPA lifecycle: preview, accept, archive, and version-update
* [BAA](/compliance/baa) — the HIPAA business associate agreement lifecycle
* [Evidence binder](/compliance/evidence-binder) — the generator: framework scope, formats, tamper flags, and worked examples
* [Compliance FAQ](/compliance/faq) — routes a first question to the page that owns it


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.