Many vendors publish their security posture on a Trust Center. Some documents are public; others are confidential and sit behind an access request that someone at the vendor has to approve. Rather than making you visit the site, request access, wait, download files, and upload them into Drata by hand, the agent does that work as part of the security review.
This matters because access requests are the slowest part of a vendor review. Waiting on a vendor administrator can take days, and a review that can't start until then is a review that sits. Collecting public documents first means you get a first-pass assessment in minutes and only revisit it when the fuller picture arrives.
Setup
Ensure the vendor's Trust Center URL is populated in their vendor profile.
Vendors with multiple products
If the vendor has multiple products on SafeBase, include the product-specific URL to target just that product.
For example:
https://trust.drata.com/?product=safebaseIf no product is specified, the agent collects documents from the vendor's default product.
Single-product Trust Centers — those without a product selector in the upper-right corner of the Trust Center — don't need a product-specific URL.
Note: If a vendor offers multiple products and you need to evaluate them separately, set up each product as a separate vendor in Drata.
You can also add vendors from the Prospective vendors search, which automatically separates each SafeBase product into its own vendor entry with the correct Trust Center link.
Trust Center URL, not a marketing page
A common mistake is entering a security marketing page rather than the Trust Center itself. Marketing pages describe a vendor's security program but don't contain the compliance documents the agent needs.
❌
https://drata.com/security— describes security information, no documents✅
https://trust.drata.com/— the actual Trust Center
If the page you're about to paste doesn't list downloadable documents and certifications, it's probably not the Trust Center.
How it works
When a vendor has a Trust Center URL, the security review includes a Get access to Trust Center step. The review checklist shows:
Review and confirm criteria
Get access to Trust Center (only when the vendor has a Trust Center URL)
Collect documents
Process documents
Assess the vendor against criteria
Review residual risk
Finalize the review and generate the report
What the Agent does at each step depends on the TPRM Agent autonomy settings.
If you already have access
The Agent collects all available documents from the SafeBase Trust Center, processes them, and continues into the assessment.
If you do not have access
The Agent can begin collecting publicly available documents and tells you so in the Drata AI panel: I'm collecting publicly available documents from the vendor's SafeBase Trust Center. No access is required for this step.
Alongside that message, you may see a Request access & re-run full assessment button. You can let the public-document assessment run, request access in parallel, or do both.
Note: Depending on the TPRM Agent settings, the Agent may proceed automatically or wait for your approval:
Step 1: Request Trust Center access from Drata
You can request access from the chat panel without leaving Drata.
Select Request access & re-run full assessment in the Drata AI panel.
In the Request access dialog, provide the information the vendor needs to review your request. The access form can be customized, as a result fields requested may vary. Drata will automatically pull the following information if populated.
First name
Last name
Work Email
Company name
Role
Select the checkbox to confirm you've read and agree to the Trust Center's and the vendor's terms. A Trust Center terms link opens the full terms.
Select Submit request, or Back to return without requesting.
The fields you're asked for depend on how the vendor has configured their Trust Center, so you may see more or fewer than those above.
After you submit, the agent confirms exactly what it sent — the name, company, and work email address used — and notes that you may be required to sign an NDA.
You'll also see two options:
Run assessment — proceed now using the public documents
Proceed without Trust Center access — continue the review without waiting
The request is submitted on your behalf using your email address, so the vendor's approval email arrives in your inbox rather than a shared mailbox.
Expected outcome: The vendor's Trust Center tab in Drata shows a status banner reading Status: Access requested, confirming the request and naming the email address where you'll receive next steps. The Drata AI panel records the details submitted.
Step 2: Complete access in your email and SafeBase
Access is granted by the vendor, not by Drata, so the next steps happen outside Drata. Here's the whole path.
The access email
When the vendor approves your request, you receive an email from their Trust Center, branded with the vendor's logo and footed with "[Vendor]'s Trust Center is powered by SafeBase."
The email:
Explains what access gives you — after accessing, you'll be able to view certificates, download confidential documents, and review standard security questionnaires. You can also subscribe to receive future updates on the vendor's security program.
Warns that the link is single-use. For security reasons, the link is valid for a single login and expires after one day.
Gives two instructions, which describe the handoff back to Drata:
Go to the vendor's Trust Center.
After a brief moment, you'll be redirected back to the Vendor Profile in Drata with additional access.
Includes an access button labeled Access the [Vendor] Trust Center.
Select that button to continue.
Note: If the link has expired, request access again from Drata to trigger a fresh email.
Authentication with SafeBase
Use the same work email address the agent submitted with your request. A different address won't be matched to the approved request.
Accepting the Trust Center terms
On first arrival you'll see a short welcome dialog — Welcome to [Vendor]'s Trust Center. By proceeding, you agree to the platform's Terms of Use. Select Let's Go to continue.
If your access is covered by an NDA, the Trust Center displays a reminder that you're viewing it under NDA. Your access status is also visible in the Trust Center's account menu, which shows what you've been granted — for example, Gained access to Trust Center and NDA signed outside of SafeBase.
Returning to Drata
Because the agent started this review, the Trust Center recognizes it and offers to send you back. You'll see a banner at the top of the page:
Pick up your review in Drata VRM — It looks like you started your review in Drata VRM. Go back to VRM to continue.
Select Go to Drata VRM to return to the vendor's profile in Drata with your new access applied. ("Drata VRM" is Drata's vendor risk management area — the same place you started.)
Expected outcome: The vendor's Trust Center tab in Drata shows that access has been granted, along with how long it lasts — the duration is set by the vendor, so check the tab rather than assuming a fixed period. The tab also invites you to add documents to your security review. The Get access to Trust Center step is checked in the agent's checklist.
Step 3: Re-run the assessment with the full document set
Once access is granted, the agent picks the review back up on its own.
You'll see a message in the Drata AI panel explaining what changed and what it proposes to do: The vendor has approved your access request! The previous assessment ran using public documents only, so I'll collect the full set of documents now and re-run the assessment with everything available.
Select Run assessment.
The agent collects the complete document set, reports how many documents it found, and begins processing — for example, Collected 13 documents from the trust center. Processing documents for the assessment. This might take a few minutes.
Everything lands in the review's Reports and documents tab, where each file shows its state as the agent works through it: Analyzing document… while in progress, then Ready for review. Where the agent finds exceptions inside a report, the row says so — for example, Review 9 exceptions found — so you can go straight to the passages that matter.
Because the agent re-evaluates every criterion against the full set, criteria that were previously inconclusive for lack of evidence may resolve to met, partially met, or not met.
Expected outcome: The review's Reports and documents tab lists the full set of Trust Center documents with their processing status, and the assessment results reflect both public and confidential documents rather than public documents alone.
Assess with public documents only
Some Trust Center documents sit behind an access request that a vendor administrator has to approve, which can take time or be declined. Rather than waiting, the agent collects whatever is public and lets you assess immediately.
When you start or open a review, the agent begins collecting public Trust Center documents right away. No access is required.
Once collected, the agent confirms how many public documents it found and flags that the assessment is based on public documents only.
Confirm your criteria to run the assessment now, or request Trust Center access first if you'd rather wait for the full set.
While the assessment runs, a Public docs only tag appears next to the progress indicator, so it's clear the results reflect public documents alone.
Note: Gaps caused by missing confidential documents typically show up as Inconclusive rather than Not Met. This lets you tell the difference between the vendor hasn't disclosed this yet and the vendor doesn't meet this criterion.
Expected outcome: You have a completed first-pass assessment within minutes of starting the review, labeled Public docs only, with undisclosed criteria marked Inconclusive rather than Not Met.
If access is denied or you'd rather not wait
The Trust Center integration is a convenience, not a requirement. You can always:
Upload documents manually to the review's Reports and documents tab
Send a questionnaire through Drata and let the agent assess the responses
Proceed with the public-documents-only assessment and finalize on that basis, noting the limitation in your review rationale
Expected outcome: The review can be completed and finalized whether or not Trust Center access was granted.
FAQ
Which URL should I use for a vendor with several products? The product-specific URL, so the agent targets the right product — for example, https://trust.drata.com/?product=safebase. Without one, the agent collects from the vendor's default product. Single-product Trust Centers don't need a product parameter.
How do I know I've got the Trust Center URL and not a marketing page? The Trust Center lists downloadable documents and certifications. A page that only describes the vendor's security program is a marketing page and won't give the agent anything to assess.
Do I have to wait for access before assessing? No. The agent collects public documents and lets you assess immediately, then re-runs with the full set once access is granted.
Who does the access request come from? You. Drata submits it on your behalf using your email address, so the vendor's approval email arrives in your inbox.
The access link in my email didn't work. Those links are valid for a single login and expire after one day. Request access again from Drata to get a fresh link.
Which email address should I sign in to SafeBase with? The same work email the agent submitted with your request. A different address won't match the approved request.
Why did SafeBase send me back to "Drata VRM"? That's Drata — SafeBase recognizes that your review started in Drata's vendor risk management area and offers to return you there with your new access applied.
How long does Trust Center access last? The vendor sets the duration. Once access is granted, the length is shown on the vendor's Trust Center tab in Drata.
Why are some criteria Inconclusive rather than Not Met? Inconclusive means the documentation didn't contain enough information to determine the answer — common when only public documents were available. Not Met means the documentation shows the requirement isn't satisfied. Re-running with confidential documents usually resolves inconclusive results.
Can I choose which Trust Center documents get used? Yes. The vendor's Trust Center tab lists the published documents and lets you add specific ones to your review.
