Trust & AI governance
Publish a self-reported, agent-readable trust profile: governance, models, and certifications.
The Trust & AI Governance profile is a public, agent-readable record of your data practices, the models you use, and your AI risk posture. It is free to publish.
At a glance
- Publish a free, public trust profile at
/manage/<your-company>/trust. - Everything is self-reported — Welcome.AI doesn't verify claims, and you can't mark your own as verified. Link out to real certifications instead.
- Eight tabs: Disclosure, Models & Subprocessors, Certifications, and Preview are free; Documents, Access, Insights, and Questionnaire are Pro.
- Served as a machine-readable
trust.jsonfeed at/company/<slug>/trust.jsonfor buyers and AI agents. - Draft vs Published: your edits stay private until you publish.
- A published profile strengthens the Trust pillar of your discoverability readiness.
Where to find it
Open /manage/<your-company>/trust in your dashboard. Use the publish toggle to switch the profile between Draft and Published. While in Draft, your edits are private; once Published, the public page and feed go live.
Self-reported, not verified
Everything in your trust profile is self-reported. Welcome.AI does not independently verify these claims, and you cannot mark your own claims as "verified." Every entry stays labelled self-reported until a third party verifies it. The honest model is the point: link out to real, externally-hosted certifications (SOC 2, ISO/IEC 42001, HITRUST AI) so buyers and agents can confirm them at the source.
Because of this, your machine-readable feed always carries the attestation "self-reported by the company; not independently verified by Welcome.AI," and it cannot be stripped — even on a custom domain.
Tabs
| Tab | Plan | What it does |
|---|---|---|
| Disclosure | Free | Data-training stance, residency, retention, provenance, responsible-AI summary, and AI risk disclosures mapped to frameworks (NIST AI RMF, ISO 42001, EU AI Act) |
| Models & Subprocessors | Free | The foundation models you use and the subprocessors you share data with |
| Certifications | Free | Links to externally-hosted certifications and attestations, each labelled self-reported |
| Documents | Pro | A gated document library buyers can request |
| Access | Pro | The request pipeline and invites for gated documents |
| Insights | Pro | Engagement analytics and an audit timeline for your trust profile |
| Questionnaire | Pro | AI-drafted answers to security questionnaires, grounded in your profile |
| Preview | Free | A live view of the public trust.json feed before and after publishing |
The public trust.json feed
Once published, your profile is served as a machine-readable feed at /company/<slug>/trust.json. AI agents and buyers fetch it to verify your credibility programmatically instead of parsing marketing copy. It carries your data governance, foundation models, subprocessors, certifications, responsible-AI policy, AI risk disclosures, derived framework annotations, and links to your other endpoints — always with the self-reported attestation and per-claim provenance. Use the Preview tab to inspect the exact feed, then "Open trust.json" to view it live.
A completed trust profile also feeds the Trust pillar of your readiness. For the terms used here, see key concepts.
FAQ
Does Welcome.AI verify the information in my trust profile?
No. Every entry is self-reported and stays labelled that way — you cannot mark your own claims as "verified." The machine-readable feed always carries the attestation "self-reported by the company; not independently verified by Welcome.AI," and it can't be stripped, even on a custom domain. Link out to externally-hosted certifications (SOC 2, ISO/IEC 42001, HITRUST AI) so buyers and agents can confirm them at the source.
Is the trust profile free?
Yes. The Disclosure, Models & Subprocessors, Certifications, and Preview tabs are free. The Documents library, Access request pipeline, Insights analytics, and AI-drafted Questionnaire answers are Pro.
What is trust.json and who uses it?
It's the machine-readable version of your published profile, served at /company/<slug>/trust.json. AI agents and buyers fetch it to assess your credibility programmatically — it carries your data governance, foundation models, subprocessors, certifications, responsible-AI policy, and AI risk disclosures, each with the self-reported attestation and per-claim provenance.
Does my profile go public the moment I edit it?
No. Use the publish toggle to move between Draft and Published. While in Draft, your edits are private; the public page and trust.json feed only go live once you publish.
Which frameworks can I map my AI risk disclosures to?
The Disclosure tab lets you annotate risks against NIST AI RMF, ISO/IEC 42001, and the EU AI Act, which then appear as derived framework annotations in your feed.