How do I set up a Trust Center in sbomify?

Business+ plan
TL;DR

Go to Settings > Trust Center, enable it, and set your custom domain. Trust Center requires a Business plan or higher.

Walkthrough

Setting up a Trust Center

The Trust Center is available on the Business plan and above. For background on what a Trust Center is and why it matters, see What is a Trust Center?.

To set up your Trust Center:

  1. Navigate to Settings
  2. Go to the Trust Center section
  3. Enable your Trust Center
  4. Set your custom domain (e.g. trust.yourcompany.com)
  5. Configure a CNAME record with your DNS provider pointing to sbomify

Once enabled, your uploaded SBOMs and compliance documents are automatically published to your Trust Center. You can see a live example at trust.sbomify.com.

Gated content

Not everything needs to be public. sbomify lets you mark components as gated, meaning visitors must request access before they can view or download the artifacts. This is useful for sensitive documents like penetration test reports or detailed SBOMs that you only want to share under certain conditions.

Gated content supports two modes:

  • With NDA -the visitor must accept your NDA before access is granted
  • Without NDA -the visitor requests access and you approve or deny it manually

Either way, you stay in control of who sees what. Approval requests show up in your sbomify dashboard so you can review them.