Trust Portal
The Trust Portal is your public, link-gated governance page. Customers, prospects and auditors see a curated, read-only summary of your AI governance posture drawn live from your registers — there is no separate content to maintain.
Where to enable it
- Go to Governance → Trust Portal in the tenant portal.
- Create the portal record and pick a slug — your page lives at /trust/<slug>. The slug is opaque and can be rotated at any time.
- Use the per-section toggles to choose what is visible: framework coverage, published policies, sub-processors and DPA status, evidence continuity, and access requests.
- Publish. Until you publish, the page is not reachable.
What visitors can see
Only the sections you enable, and only summary-level figures. Record contents, evidence files, ledger volumes and gap dates are never exposed publicly. Visitors who need more can submit an access request, which lands in the portal's inbox for you to approve — optionally behind an NDA acceptance step.
The pre-publish evidence check
Before the portal goes public, RAIC runs an integrity check on the evidence the page implicitly vouches for. Findings are either blocking or advisory. Blocking means our own public verifier would fail the claim, so publishing is prevented. Advisory means the chain verifies but the operational record was imperfect — you may publish after acknowledging it, and the exact figures on screen are stored with your acknowledgement.
- Blocking — audit ledger chain does not verify
- One or more chain breaks were detected in the published window. Contact support; breaks are investigated rather than dismissed.
- Blocking — governance decision chain does not verify
- Decision records in the window failed hash verification.
- Blocking — decisions not inside a sealed day
- Recent decisions have not been sealed yet. Seals run nightly; re-open the check after the next seal completes.
- Blocking — days with activity were never sealed
- A past day recorded activity but was never sealed and is now outside its grace window. Support can re-run the seal for those days.
- Advisory — days sealed after the grace window
- Sealing ran late. The chain still verifies; publishing is allowed.
- Advisory — coverage below 100%
- Visitors will see the framework gap. Coverage is yours to publish at any level and never blocks publishing.
- Advisory — chain breaks before the published window
- Historic issues outside the window you are publishing. Noted for the record only.
If publishing is blocked
- Read the top finding — it names the exact condition, not a generic failure.
- If it names unsealed decisions, wait for the next nightly seal and re-open the check.
- If it names missed seals or chain breaks, raise a support request; those are resolved server-side and are not something you can clear from the UI.
- Re-open the check after each remediation — it re-reads live figures every time it opens.
Keeping it current
- Content refreshes from your live registers — updating a policy or control updates the portal.
- Visits are logged so you can see interest from prospects and customers.
- Rotate the slug to revoke a previously shared link without taking the portal down.
- Unpublish at any time; the public URL immediately stops resolving.
Related documentation
- Verifiable Evidence Lineage — the sealed history behind the pre-publish check.
- Portable Continuity Badge — publish sealed continuity on your own website.
- Auditor Recognition Kit — what an external auditor can verify independently.
