River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Sales Security Trust Package

Four documents and three sheets that carry what each file actually covers, how far short of today it stops, and who is holding it.

Free download  ·  No account needed

Safe to send, 4 September

Larkfield Systems, package requested by Halberd Capital

Documents held13, plus 2 a buyer has asked for and we have never had
Safe to send today8
Blocked3, all on coverage rather than content
Already out at a superseded version5 copies, 4 of them at a live account

1. What the buyer asked for, against what we hold

Their askAnswered byVerdict
An audit report covering availabilitySOC 2 Type 2, FY25Partial, Availability not in scope
A current audit reportFY25 plus bridge letterStale, coverage ended 248 days ago
ISO 27001 certificateNothingMissing, not certified
Proof the DR plan has been testedDR plan v4Partial, EU failover untested
Evidence of encryption at restPolicy set v6 and the FY25 controlCovered

2. The blocker

The bridge letter meant to carry the report forward was issued on 14 February and is now 203 days old. Sending it reads worse than sending nothing, because it shows the gap was noticed in February and then left.

3. The sentence

Reissue the bridge letter today, then send four documents with a coverage note that names Availability, the EU failover and the missing certificate on its first page.

Three of the five asks are answered by a document we hold. Not one of them is answered by the document the buyer named.

Search this and page one agrees on the build. A plain-language security overview, the audit report gated behind an NDA, a penetration test summary carrying its date, firm and scope, a sub-processor list, a DPA. Then a three-tier access model: public for discovery, request for the report, agreement for the architecture. It is good advice and it is now the standard. It also describes a folder, and a folder has exactly one state.

A document has three, and each one decides a review. Coverage, because an audit report speaks to a period that closed, and the first number a reviewer works out is today minus that date. Scope, because a report examining two criteria categories does not answer a question about a third. Expiry, because it is published rather than private: a CSA STAR attestation listing lapses after a year, and a DPA annexing the 2010 clauses died on 27 December 2022.

The fourth thing no folder holds is a memory of who has your documents. A restricted report sits in an inbox at a version you replaced in June, at a company where the deal died in March. So the register carries coverage and scope, and the log carries names and versions. The answers themselves belong to the security questionnaire response pack, the markup that comes back is separate again, and the rest sits in the template library and the tool index.

What each document covers, what it does not, and who is already holding it

Document Register with a coverage period rather than an issue date, Coverage Against Asks built from one buyer's own words, and the Distribution Log that answers the reverse question.

Document Register

Illustrative rows for a fictional SaaS vendor. The last two rows are documents that do not exist, which is a state the register has to be able to hold.

DocumentVersionCoverage endsDays shortDoes not coverReleaseStatus
SOC 2 Type 2 reportFY2531 Dec 2025248Availability, Processing Integrity, PrivacyAgreementCoverage ended
Bridge letter14 Feb 202614 Feb 2026203Anything after its own signature dateAgreementReissue first
Penetration test summaryMar 202614 Mar 2026175Mobile client, admin console, partner APIAgreementCurrent
Penetration test full reportMar 202614 Mar 2026175Never leavesInternal
CSA STAR self-assessmentCAIQ v4.0.222 Nov 2026Not yetAnything a third party has testedPublicLapses in 79 days
Data processing agreementv2.427 Dec 20221347Annexes the withdrawn clausesWithdrawnTwo customers still on it
Cyber Essentials certificateJan 20268 Jan 2027Not yetThe Dublin entity and the production estatePublicCurrent
Business continuity and DR planv4No coverage endn/aEU region failover has never been testedAgreementCurrent
HECVAT FullNoneNonen/aDoes not exist, requested 4 Aug
ISO 27001 certificateNoneNonen/aDoes not exist, not certified

The days-short column is the whole sheet. Every one of these documents is real, signed and filed, and three of them cannot go to a buyer this week without a sentence explaining the number in that column.

Coverage end is never filled with an issue date. The DR plan has no coverage end and says so, because a recovery plan is current until it is replaced and a report is current until a specific Tuesday in December.

Coverage Against Asks

Built per buyer, from their words rather than yours. Five verdicts, and every row carries what actually goes back.

What they asked forWho askedVerdictThe gapWhat goes back
An audit report covering availabilityHalberd CapitalPartialAvailability is not a category in our reportSay so first, send the uptime record and the DR test result, name the FY26 scope date
A current audit reportNorthmoor HealthStaleCoverage ended 31 December, bridge letter 203 days oldReissue the bridge letter, then send both with the fieldwork date
HECVAT FullBrightwater UniversityMissingNever completed oneThe CAIQ mapped across question by question, plus a date for the HECVAT
Penetration test of the mobile appKirkwall RetailOut of scopeMobile client was not testedThe tested scope quoted verbatim, and the 5 October engagement
ISO 27001 certificateHalberd CapitalMissingNot certified, not pursuing itThe STAR listing and the report covering the same control ground
Evidence of encryption at restNorthmoor HealthCoveredNonePolicy set v6 and the FY25 control description
Where our data is storedBrightwater UniversityCoveredNoneSeptember sub-processor list and DPA v3.1
A signed DPA with current transfer clausesKirkwall RetailCoveredNonev3.1, with written confirmation that v2.4 is withdrawn

Four of the eight asks are not covered by the document the buyer named. Every one of those four still has a send against it, because a verdict with nothing attached is a finding rather than an answer.

This is the sheet the coverage note is written from. Anything not marked covered appears on the front page of the package, in the buyer's own words, before their reviewer opens a file.

Distribution Log

Every release by person and version. The useful query is the reverse one: who is holding the thing you replaced.

SentDocumentVersionWho has itBasisDealAction
14 FebSOC 2 Type 2FY25H. Vance, Halberd CapitalNDA 6 FebWonSend the reissued bridge letter
3 AprPen test summaryMar 2026J. Okafor, Northmoor HealthMutual NDA 28 MarLost 19 JunNone, the NDA runs to 2029
11 JunPolicy setv5S. Prentice, Halberd CapitalNDA 6 FebWonSend v6 and say what changed
9 JulSOC 2 Type 2FY25T. Iles, Kirkwall RetailNone on fileLiveGet the NDA signed, retire the copy
18 AugSub-processor list14 JulProcurement, Brightwater UniversityPublicLiveSend the September list
1 SepDR planv3S. Prentice, Halberd CapitalNDA 6 FebWonSend v4 with the EU gap flagged

The 9 July row is the one this log exists for. A restricted report went to a live account with no agreement covering it, and no folder, tier model or trust centre anywhere would surface that, because the release left no trace behind.

Four of the six rows are a live account holding something superseded. Sending the replacement unprompted is an afternoon of email that lands before their next review rather than during it.

What's in the pack

01

Document Register

One row per document with the period it covers, the days that period stops short of today, the scope it does not cover, its release class and any successor in flight.

02

Coverage Against Asks

Built per buyer from their own words, with five verdicts of covered, partial, stale, out of scope or missing, and what actually goes back against every row.

03

Distribution Log

Every release by person, version and basis, so the reverse query works: who is holding the report you replaced, and which release had no agreement behind it.

04

Coverage Note

The front page of the package, naming every gap before their reviewer finds one. A stated limit reads as control; a discovered one costs a round trip.

05

Trust Overview

The public one-pager that answers most of a first pass with nothing signed, including what you do not hold and are not pursuing.

06

Policy Summaries

One paragraph per policy naming its version, approval date, next review and the two things a reviewer is actually checking it for.

07

Redaction Guidance

What never leaves, what comes out for a public release, and the four things you must never redact however uncomfortable they are.

How to use it

  1. 1

    Open in River, or take it blank

    Open the pack in River and send it your documents, or download the Word documents and CSV sheets and fill them in yourself.

  2. 2

    Send whole files

    The coverage period and the scope statement live on the opinion letter and the certificate face, and both disappear the moment anyone summarises them.

  3. 3

    Build the register first

    Nothing else works without it. Coverage end, days short, what it does not cover, release class, and rows for the documents you do not have.

  4. 4

    Assemble against their asks

    Match this buyer's questions to your documents, write the coverage note from everything not marked covered, then log what went out.

Frequently asked questions

Is this template free?

Yes. Four Word documents and three CSV sheets, downloaded as a zip, no signup. River is the optional half: it reads your documents for their real coverage and scope, dates them against today, and assembles the package per buyer. Single-shot jobs live in the tool index.

We already have a trust centre. Does this replace it?

It feeds it. A trust centre is the delivery surface and it publishes whatever state your documents are in. The register is what tells you that state: which report's coverage ended in December, which certificate lapses in eleven weeks, which listing the buyer can already see is stale.

Why track coverage instead of an expiry date?

Because most assurance documents have no expiry. An audit report covers a period and then stops, and a reviewer computes today minus that end date in about ten seconds. A certificate does expire, and the register holds both without pretending they are the same thing.

Is the distribution log not just admin?

It answers one question nothing else can: who is holding the version you replaced. Four live accounts holding a superseded policy set is an afternoon of email that lands before their next review. A restricted report with no agreement on file is worth finding today, before it ages into a stalled review the security review tracker would have priced.

Should we really write down what we do not cover?

Yes, and first. A reviewer's job is to find the edges of what you evidenced. Every edge you name costs nothing and reads as control. Every edge they find costs a round trip and some standing, and they will find all of them. For the audit report specifically, the SOC 2 summary names those edges question by question.

The buyer will check our claims anyway.

They will, which is the argument for the register. Current Cyber Essentials certificates sit in a public searchable register, and self-assessment listings carry their own dates. A claim on your site that the public record contradicts is worse than no claim.

Where do the questionnaire answers fit?

Somewhere else. This space owns the documents and what they cover; the security questionnaire response pack owns the answers and the evidence behind each one. Documents feed answers, so the register is what an answer cites when it names a source.

Find out what is safe to send today

Take the Word documents and CSV sheets blank, or open this exact pack in River and let it read your documents for their real coverage first.

Edit with AI