# trustlists > trustlists is an open directory of company trust centers, security pages, compliance documentation, and trust-center platform metadata. Use trustlists to locate a vendor's official trust center during security review, GRC, procurement, or compliance research. Directory records link to third-party sources; verify material claims and document availability with the vendor before relying on them. The public directory and JSON data are free to access. trustlists Companion and the SOC 2 Analyzer are separate account-based product experiences. For programmatic use, prefer the public JSON endpoints and agent resources below. Request `Accept: text/markdown` on the directory or a `/company/{slug}/` page for a clean markdown rendition. ## Directory - [Trust center directory](https://trustlists.org/): Search and browse the full company directory. - [CSA STAR directory](https://trustlists.org/csa-star/): Browse companies with CSA STAR registry coverage. - [AI-readable overview](https://trustlists.org/ai/): Structured background, scope, use cases, and official resources. ## APIs and agent resources - [Trust center dataset](https://trustlists.org/api/trust-centers.json): Public JSON dataset with company, website, trust center, platform, certification, and verification fields. - [Directory statistics](https://trustlists.org/api/stats.json): Public JSON counts by trust-center platform. - [API documentation](https://trustlists.org/developers/): Endpoint details, response fields, examples, and attribution requirements. - [MCP server](https://trustlists.org/mcp/): Connect Cursor, Claude, and other MCP clients to search, lookup, browse, and dependency-mapping tools. - [API health](https://trustlists.org/api/health): Service status for automated monitoring. - [API catalog](https://trustlists.org/.well-known/api-catalog): RFC 9727 API catalog in linkset JSON format. - [Agent skills index](https://trustlists.org/.well-known/agent-skills/index.json): Machine-readable discovery document for trustlists agent skills. - [Sitemap](https://trustlists.org/sitemap.xml): Index of public, human-readable pages. ## Agent skills - [List trust centers](https://trustlists.org/.well-known/agent-skills/list-trust-centers.md): Retrieve the complete public directory. - [Lookup a trust center](https://trustlists.org/.well-known/agent-skills/lookup-trust-center.md): Match a company name or domain to its trust center. - [Get company details](https://trustlists.org/.well-known/agent-skills/get-company-details.md): Retrieve one company's platform, certifications, and official trust-center link. ## Policies - [Privacy Policy](https://trustlists.org/privacy/): Data collection, product data, payments, processors, retention, rights, and security. - [Terms of Service](https://trustlists.org/terms/): Terms covering the directory, accounts, paid credits, and AI-assisted features. - [Listing Removal and Correction Policy](https://trustlists.org/removal-policy/): How a company representative can request removal, correction, or listing verification. ## Optional - [trustlists Companion](https://app.trustlists.org/): Account-based product workspace and SOC 2 analysis tools. - [Chrome extension](https://chromewebstore.google.com/detail/trustlists/mcgjphnhdcndknmmmdemhgcbdhlmghni): Browser companion for trust-center discovery. - [trustlists blog](https://trustlists.org/blog/): Practical vendor-review and compliance guides. - [GitHub data repository](https://github.com/trustlists/trustlists-data): Open data source and contribution workflow.