Sales Security Trust Package
Four documents and three sheets that carry what each file actually covers, how far short of today it stops, and who is holding it.
Free download · No account needed
Safe to send, 4 September
Larkfield Systems, package requested by Halberd Capital
| Documents held | 13, plus 2 a buyer has asked for and we have never had |
| Safe to send today | 8 |
| Blocked | 3, all on coverage rather than content |
| Already out at a superseded version | 5 copies, 4 of them at a live account |
1. What the buyer asked for, against what we hold
| Their ask | Answered by | Verdict |
|---|---|---|
| An audit report covering availability | SOC 2 Type 2, FY25 | Partial, Availability not in scope |
| A current audit report | FY25 plus bridge letter | Stale, coverage ended 248 days ago |
| ISO 27001 certificate | Nothing | Missing, not certified |
| Proof the DR plan has been tested | DR plan v4 | Partial, EU failover untested |
| Evidence of encryption at rest | Policy set v6 and the FY25 control | Covered |
2. The blocker
The bridge letter meant to carry the report forward was issued on 14 February and is now 203 days old. Sending it reads worse than sending nothing, because it shows the gap was noticed in February and then left.
3. The sentence
Reissue the bridge letter today, then send four documents with a coverage note that names Availability, the EU failover and the missing certificate on its first page.
Three of the five asks are answered by a document we hold. Not one of them is answered by the document the buyer named.
Search this and page one agrees on the build. A plain-language security overview, the audit report gated behind an NDA, a penetration test summary carrying its date, firm and scope, a sub-processor list, a DPA. Then a three-tier access model: public for discovery, request for the report, agreement for the architecture. It is good advice and it is now the standard. It also describes a folder, and a folder has exactly one state.
A document has three, and each one decides a review. Coverage, because an audit report speaks to a period that closed, and the first number a reviewer works out is today minus that date. Scope, because a report examining two criteria categories does not answer a question about a third. Expiry, because it is published rather than private: a CSA STAR attestation listing lapses after a year, and a DPA annexing the 2010 clauses died on 27 December 2022.
The fourth thing no folder holds is a memory of who has your documents. A restricted report sits in an inbox at a version you replaced in June, at a company where the deal died in March. So the register carries coverage and scope, and the log carries names and versions. The answers themselves belong to the security questionnaire response pack, the markup that comes back is separate again, and the rest sits in the template library and the tool index.
What's in the pack
Document Register
One row per document with the period it covers, the days that period stops short of today, the scope it does not cover, its release class and any successor in flight.
Coverage Against Asks
Built per buyer from their own words, with five verdicts of covered, partial, stale, out of scope or missing, and what actually goes back against every row.
Distribution Log
Every release by person, version and basis, so the reverse query works: who is holding the report you replaced, and which release had no agreement behind it.
Coverage Note
The front page of the package, naming every gap before their reviewer finds one. A stated limit reads as control; a discovered one costs a round trip.
Trust Overview
The public one-pager that answers most of a first pass with nothing signed, including what you do not hold and are not pursuing.
Policy Summaries
One paragraph per policy naming its version, approval date, next review and the two things a reviewer is actually checking it for.
Redaction Guidance
What never leaves, what comes out for a public release, and the four things you must never redact however uncomfortable they are.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and send it your documents, or download the Word documents and CSV sheets and fill them in yourself.
- 2
Send whole files
The coverage period and the scope statement live on the opinion letter and the certificate face, and both disappear the moment anyone summarises them.
- 3
Build the register first
Nothing else works without it. Coverage end, days short, what it does not cover, release class, and rows for the documents you do not have.
- 4
Assemble against their asks
Match this buyer's questions to your documents, write the coverage note from everything not marked covered, then log what went out.
Frequently asked questions
Is this template free?
Yes. Four Word documents and three CSV sheets, downloaded as a zip, no signup. River is the optional half: it reads your documents for their real coverage and scope, dates them against today, and assembles the package per buyer. Single-shot jobs live in the tool index.
We already have a trust centre. Does this replace it?
It feeds it. A trust centre is the delivery surface and it publishes whatever state your documents are in. The register is what tells you that state: which report's coverage ended in December, which certificate lapses in eleven weeks, which listing the buyer can already see is stale.
Why track coverage instead of an expiry date?
Because most assurance documents have no expiry. An audit report covers a period and then stops, and a reviewer computes today minus that end date in about ten seconds. A certificate does expire, and the register holds both without pretending they are the same thing.
Is the distribution log not just admin?
It answers one question nothing else can: who is holding the version you replaced. Four live accounts holding a superseded policy set is an afternoon of email that lands before their next review. A restricted report with no agreement on file is worth finding today, before it ages into a stalled review the security review tracker would have priced.
Should we really write down what we do not cover?
Yes, and first. A reviewer's job is to find the edges of what you evidenced. Every edge you name costs nothing and reads as control. Every edge they find costs a round trip and some standing, and they will find all of them. For the audit report specifically, the SOC 2 summary names those edges question by question.
The buyer will check our claims anyway.
They will, which is the argument for the register. Current Cyber Essentials certificates sit in a public searchable register, and self-assessment listings carry their own dates. A claim on your site that the public record contradicts is worse than no claim.
Where do the questionnaire answers fit?
Somewhere else. This space owns the documents and what they cover; the security questionnaire response pack owns the answers and the evidence behind each one. Documents feed answers, so the register is what an answer cites when it names a source.
Find out what is safe to send today
Take the Word documents and CSV sheets blank, or open this exact pack in River and let it read your documents for their real coverage first.
Edit with AI