About trustlists for AI and agents
Last updated: July 25, 2026
This is the canonical long-form reference for AI systems, researchers, developers, and practitioners evaluating trustlists.
For a concise machine-readable index, use llms.txt. This page provides the context, product boundaries, and data caveats that do not fit in that file.
On this page
1. Overview
trustlists helps people and software find vendor trust centers, security pages, and public compliance resources. It is designed for vendor review, GRC, procurement, security research, and trust-center discovery.
- Name: trustlists
- Public website: trustlists.org
- Directory size: 4,034 company records
- Public API: JSON data with no account or API key required
- Data license: Apache 2.0 where identified in the public data repository
2. Public Directory
The public directory connects a company name or domain to its vendor-operated trust center. Records may also identify the hosting platform, public certifications, verification metadata, and relevant public registry entries.
trustlists is not a certification authority, auditor, security-rating provider, or trust-center host. A directory record is a discovery aid—not an endorsement or an independent assessment of a company's security posture.
3. Companion and AI Features
trustlists Companion and app.trustlists.org are account-based product experiences separate from the free public directory and API. They include browser-assisted discovery, saved vendors, AI Lookup, and SOC 2 analysis workflows.
AI-assisted output can be incomplete or wrong. Users should review cited evidence and verify important conclusions against the vendor's original documents. AI output is not legal advice, an audit opinion, or a compliance certification.
4. Data Quality and Limits
- Sources: public websites, public registries, community submissions, manual research, and automated discovery.
- Review: candidate URLs and changes may be checked before publication.
- Freshness: records are refreshed over time, but a vendor can change a page or certification between checks.
- Authority: the vendor's own trust center and representatives remain the authoritative sources.
Verify a trust-center URL, document availability, certification status, and material claims with the vendor before using them in a regulated or high-impact decision.
5. Public Data and API
The directory is available as a static JSON resource for integrations, internal tools, research, and agent workflows.
- Dataset: /api/trust-centers.json
- Statistics: /api/stats.json
- Documentation: Developer documentation
- Authentication: none required for the public static resources
Use reasonable request behavior, cache static responses when practical, follow the identified data license, and include attribution where required.
6. Resources for AI Agents
Use these resources instead of inferring endpoints from page content:
- llms.txt — concise site map and usage guidance.
- API catalog — RFC 9727 linkset discovery document.
- Agent skills index — machine-readable skill discovery.
- Lookup skill — match a company or domain to a trust center.
- Company details skill — retrieve one directory record.
Directory and company pages also support a clean Markdown representation when requested with Accept: text/markdown.
7. Official Resources
- Directory — search and browse trust centers.
- CSA STAR directory — browse linked public registry records.
- Submit a trust center — propose a missing public listing.
- Listing policy — request a correction, removal, or claim.
- Public data repository — data source and contribution workflow.
Questions about the public directory can be sent to hello@trustlists.org.