TrustedSite
United States · www.trustedsite.com · 21 vendors
Resilience scores
- Digital Sovereignty: 62
- Digital Resilience: 6
- Financial Resilience: 6
Technology vendors
- Adobe Inc. — Technology — United States
- BlockSurvey — United States
- GoDaddy Inc. — Technology — United States
- and 19 more
Services catalogue
2 services in catalogue across 1 category; runs on 21 sub-vendors.
- Certification
- TrustedSite
Insights
Last updated 2026-08-14 · revision 1
21 direct vendors, 203 subvendors
Direct vendors by controlling owner country (sample)
- United Kingdom: 1
- Vietnam: 1
- France: 1
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Luxembourg: 1
- Germany: 6
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
TrustedSite exhibits a medium level of migration readiness. The existing use of AWS CloudFront indicates some familiarity with cloud environments, and their SOC 2 Type II and PCI DSS compliance suggests a disciplined operational framework that could facilitate a structured migration. The company's expertise in security and vulnerability assessment also implies a good understanding of their own systems, which is beneficial for migration planning. However, several critical unknowns and potential challenges limit a higher readiness score. There is no explicit information regarding the cloud-nativeness, containerization, or microservices architecture of their core applications, making it difficult to assess the complexity of migrating these services. Furthermore, crucial data is missing regarding the regulatory environment and specific data residency requirements, which are fundamental considerations for any cloud migration. Financial stability data (revenue concentration, growth history) is also absent, making it impossible to assess the company's capacity to fund a significant migration effort. The vendor landscape presents ambiguity; while there is geographic diversity among vendor countries, the 'Total Vendors: 0' data point, combined with 'Total Services: 25' and 'Vendor Lock-in Risk: Unknown', makes it challenging to determine the level of vendor lock-in, which could significantly impact migration complexity and cost.
Compliance
7 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
No evidence of ISO 27001 certification was found on TrustedSite's website or public documentation. However, TrustedSite has achieved SOC2 Type 2 compliance and is a PCI DSS Approved Scanning Vendor, demonstrating a mature information security management posture. ISO 27001 and SOC2 Type 2 have significant overlap in security controls, and many companies that achieve SOC2 Type 2 do not separately pursue ISO 27001 certification (particularly US-based companies where SOC2 is the dominant standard). Risk is Low because: (1) the company has demonstrated security maturity through SOC2 Type 2 and PCI DSS ASV; (2) ISO 27001 is not legally mandated for TrustedSite's industry or jurisdiction; (3) absence of ISO 27001 does not indicate non-compliance with applicable regulations.
Evidence: https://www.trustedsite.com/company/, https://www.trustedsite.com
EU-U.S. Data Privacy Framework — Compliant
TrustedSite has self-certified under the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. DPF, as explicitly stated in their privacy policy. The DPF replaced the invalidated Privacy Shield framework and provides a legal mechanism for transferring personal data from the EU/UK/Switzerland to the US. Risk is Medium rather than Low because: (1) the DPF has faced legal challenges and could potentially be invalidated by the Court of Justice of the EU (as happened with Safe Harbor and Privacy Shield); (2) self-certification requires annual renewal and ongoing compliance with DPF Principles; (3) TrustedSite must maintain compliance with all DPF Principles including onward transfer requirements, data integrity, access rights, and recourse mechanisms. The DPF is currently valid and enforceable, making this a Medium rather than High risk.
Evidence: https://www.trustedsite.com/privacy, https://www.trustedsite.com/data-privacy-framework, https://www.dataprivacyframework.gov/
SOC 2 (source) — Compliant
TrustedSite has publicly achieved SOC2 Type 2 compliance, as evidenced by the AICPA SOC badge prominently displayed on their homepage, privacy page, and terms page, with a direct link to aicpa.org/soc4so. The company's 'About Us' page explicitly states 'TrustedSite achieves SOC2 Type 1 Compliance' and 'SOC 2 Type II Compliant' as milestones. SOC2 Type 2 is the more rigorous standard, covering operational effectiveness of controls over a period of time (typically 6-12 months). As a cloud-based SaaS provider serving 400,000+ businesses with security scanning, trust certification, and identity protection services, SOC2 is highly relevant and the company has demonstrably achieved it. Risk is Low given confirmed compliance.
Evidence: https://www.trustedsite.com, https://www.trustedsite.com/company/, https://aicpa.org/soc4so, https://www.trustedsite.com/privacy
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
TrustedSite demonstrates qualitative financial resilience through a mature 20+ year operating history, a recurring SaaS revenue model, and a diversified customer base of over 400,000 certified sites spanning SMB and enterprise segments. The company has two distinct product lines (TrustedSite Certification and Halo Security), reducing single-product risk, and holds meaningful compliance credentials (SOC 2 Type II, PCI ASV) that reduce enterprise sales friction. Founder and insider continuity, including involvement from former McAfee Vice Chairman Todd Gebhart, supports operational stability. However, resilience is constrained by several factors. The company is privately held with no public financial disclosures, making external verification of revenue, EBIT, or equity impossible. Key-person risk materialized in 2022 when founder/CEO Tim Dowling passed away, with succession by Lisa Dowling whose background is outside SaaS. Competitive pressure from native trust signals on platforms like Shopify, Google Customer Reviews, and Trustpilot, combined with declining consumer reliance on third-party trust badges, poses category-maturity risk. The retirement of the McAfee SECURE brand in 2021 may have reduced brand halo. Without access to public capital markets, growth capital depends on internal cash flow or private raises.
Key strengths: 20+ year operating history across predecessor entities, Recurring SaaS subscription revenue model, Diversified customer base of 400,000+ certified sites, Two product lines: TrustedSite Certification and Halo Security, SOC 2 Type II and PCI DSS ASV compliance credentials, Named enterprise customers including Dollar Tree, Experian, SurveyMonkey, Omaha Steaks, Penske, Founder/insider ownership continuity with ex-McAfee leadership involvement
Risk factors: Key-person risk following 2022 death of founder/CEO Tim Dowling, Leadership transition to CEO without prior SaaS experience, Competitive pressure from native platform trust signals (Shopify, Google, Trustpilot), Retirement of McAfee SECURE brand may have reduced brand halo, Category maturity risk as consumer reliance on trust badges declines, No public capital markets access; dependent on internal cash flow, Opaque financials with no disclosed revenue, EBIT, or equity
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.