Welcome.AIWelcome.AI
    Skip to content

    Trust & AI governance

    Publish a self-reported, agent-readable trust profile: governance, models, and certifications.

    The Trust & AI Governance profile is a public, agent-readable record of your data practices, the models you use, and your AI risk posture. It is free to publish.

    At a glance

    • Publish a free, public trust profile at /manage/<your-company>/trust.
    • Everything is self-reported — Welcome.AI doesn't verify claims, and you can't mark your own as verified. Link out to real certifications instead.
    • Eight tabs: Disclosure, Models & Subprocessors, Certifications, and Preview are free; Documents, Access, Insights, and Questionnaire are Pro.
    • Served as a machine-readable trust.json feed at /company/<slug>/trust.json for buyers and AI agents.
    • Draft vs Published: your edits stay private until you publish.
    • A published profile strengthens the Trust pillar of your discoverability readiness.

    Where to find it

    Open /manage/<your-company>/trust in your dashboard. Use the publish toggle to switch the profile between Draft and Published. While in Draft, your edits are private; once Published, the public page and feed go live.

    Self-reported, not verified

    Everything in your trust profile is self-reported. Welcome.AI does not independently verify these claims, and you cannot mark your own claims as "verified." Every entry stays labelled self-reported until a third party verifies it. The honest model is the point: link out to real, externally-hosted certifications (SOC 2, ISO/IEC 42001, HITRUST AI) so buyers and agents can confirm them at the source.

    Because of this, your machine-readable feed always carries the attestation "self-reported by the company; not independently verified by Welcome.AI," and it cannot be stripped — even on a custom domain.

    Tabs

    TabPlanWhat it does
    DisclosureFreeData-training stance, residency, retention, provenance, responsible-AI summary, and AI risk disclosures mapped to frameworks (NIST AI RMF, ISO 42001, EU AI Act)
    Models & SubprocessorsFreeThe foundation models you use and the subprocessors you share data with
    CertificationsFreeLinks to externally-hosted certifications and attestations, each labelled self-reported
    DocumentsProA gated document library buyers can request
    AccessProThe request pipeline and invites for gated documents
    InsightsProEngagement analytics and an audit timeline for your trust profile
    QuestionnaireProAI-drafted answers to security questionnaires, grounded in your profile
    PreviewFreeA live view of the public trust.json feed before and after publishing

    The public trust.json feed

    Once published, your profile is served as a machine-readable feed at /company/<slug>/trust.json. AI agents and buyers fetch it to verify your credibility programmatically instead of parsing marketing copy. It carries your data governance, foundation models, subprocessors, certifications, responsible-AI policy, AI risk disclosures, derived framework annotations, and links to your other endpoints — always with the self-reported attestation and per-claim provenance. Use the Preview tab to inspect the exact feed, then "Open trust.json" to view it live.

    A completed trust profile also feeds the Trust pillar of your readiness. For the terms used here, see key concepts.

    FAQ

    Does Welcome.AI verify the information in my trust profile?

    No. Every entry is self-reported and stays labelled that way — you cannot mark your own claims as "verified." The machine-readable feed always carries the attestation "self-reported by the company; not independently verified by Welcome.AI," and it can't be stripped, even on a custom domain. Link out to externally-hosted certifications (SOC 2, ISO/IEC 42001, HITRUST AI) so buyers and agents can confirm them at the source.

    Is the trust profile free?

    Yes. The Disclosure, Models & Subprocessors, Certifications, and Preview tabs are free. The Documents library, Access request pipeline, Insights analytics, and AI-drafted Questionnaire answers are Pro.

    What is trust.json and who uses it?

    It's the machine-readable version of your published profile, served at /company/<slug>/trust.json. AI agents and buyers fetch it to assess your credibility programmatically — it carries your data governance, foundation models, subprocessors, certifications, responsible-AI policy, and AI risk disclosures, each with the self-reported attestation and per-claim provenance.

    Does my profile go public the moment I edit it?

    No. Use the publish toggle to move between Draft and Published. While in Draft, your edits are private; the public page and trust.json feed only go live once you publish.

    Which frameworks can I map my AI risk disclosures to?

    The Disclosure tab lets you annotate risks against NIST AI RMF, ISO/IEC 42001, and the EU AI Act, which then appear as derived framework annotations in your feed.