Welcome offer: 50% off your first 3 months
New customers only. Applied automatically at checkout.
Customer guide · Last verified 10 August 2026
Whistic is generally the broader security-assurance and vendor-risk platform: public Trust Centers, NDA-controlled access, questionnaires and supplier assessments in one place. VendorLens is the narrower, document-centric option for lean teams that want a branded trust center with published, self-serve pricing. This page sets out what each one actually does, and when a different tool fits better.
These products overlap on one screen — a public trust center — and diverge everywhere else. Which side of that divide you are on decides the answer.
You are the company being reviewed. Customers want your SOC 2 report, DPA and policies, and you want one place to send them instead of an email thread per deal.
You review other companies as well as being reviewed. That is assurance and third-party risk work, which is a different job from publishing your own documents.
You have a handful of documents and a recurring request, and you are checking whether a full assurance platform is more than you need right now.
Both publish a public trust center with controlled document access. The differences are scope, discovery and how pricing works.
| Criterion | VendorLens | Whistic |
|---|---|---|
| Primary use case | Publishing and controlling access to the security documents you already have | Security assurance and vendor risk: publishing your posture and assessing other companies |
| Public Trust Center | Yes — one branded public trust center per company | Yes — public Trust Centers, and more than one can be published |
| Security-document library | Yes — reports, certificates, policies and subprocessor lists, per-document access levels | Yes — documents and evidence attached to your profile and Trust Centers |
| NDA / access approvals | All plans: NDA acceptance, manual approval, time-limited links, watermarked PDFs | Yes — built-in NDA workflows, controlled access, request approvals and access duration settings |
| Custom domain | Pro plan: your own subdomain, e.g. trust.yourcompany.com | Yes — custom URLs can be configured for public Trust Centers |
| Questionnaires / self-assessments | Outbound only — VendorLens sends questionnaire packs to your suppliers (Vendor Assessments, Beta); it does not host or auto-answer inbound customer questionnaires | Yes — standard questionnaires and self-assessments are part of the platform |
| Trust Center marketplace / exchange | No — your trust center is reached through your own link or domain | Yes — profiles can be surfaced through the Whistic Trust Center Exchange |
| Broader TPRM / supplier-review functionality | Lightweight — supplier questionnaires, evidence, inherent/residual risk and recorded decisions (Beta), but not enterprise TPRM | Yes — assessing, scoring and tracking your own third parties is a core part of the platform |
| Pricing transparency | Published: free, $99/mo and $299/mo | Not published: pricing is plan-dependent and quoted by Whistic. A free Basic Profile exists with documented limits |
| Best-fit organisation | Lean B2B teams that already hold their documents and want self-serve pricing | Teams running a structured assurance or vendor-risk programme, often with a dedicated owner |
VendorLens plan details, including which tier unlocks a custom domain, are published on the pricing page.
If questionnaires are the real workload, read our take on the security questionnaire alternative before deciding.
See what the customer-facing result looks like on the vendor due-diligence portal page.
There is no single winner here. Each of these solves a different part of the security review, and the right pick depends on which part costs you the most time.
Conveyor positions itself around answering security reviews and questionnaires, with a customer-facing trust page alongside it. Worth a look if the questionnaire itself is your bottleneck rather than the documents.
Vanta is built around getting and staying compliant — monitoring controls and collecting evidence — and includes a trust page. A fit when the audit programme, not the sharing, is the main project.
Drata offers compliance automation, and SafeBase (now part of Drata) is a dedicated trust center product with access controls. Relevant if you want both halves from one vendor.
Secureframe focuses on automating compliance across several frameworks, with trust-page functionality included. Consider it when you are certifying against more than one standard.
HyperComply is aimed at turning around security questionnaires quickly, with document sharing around it. Useful where long custom questionnaires arrive regularly.
Moving a trust center is mostly a content and DNS exercise. The parts that need thought are what stays public and what does not move at all.
Export or collect the current versions of every report, certificate, policy, DPA and subprocessor list that sits on your existing profile. Version and date them before they move.
Certifications and overviews usually work as public downloads. Audit reports, pen-test detail and insurance evidence usually belong behind an NDA request with approval.
If customers already know a Whistic custom URL, keep it live while you publish the new trust center on your own subdomain, then update links in email templates, proposals and your security page.
Questionnaire history, self-assessment responses, exchange presence and any vendor assessments you ran on your own suppliers are platform-specific. If you rely on them, plan to keep them where they are or replace them separately.
Open the live demo trust portal, try a gated document request, then start free if it fits. Pricing is published — no quote needed.