# Orbiq — Trust Center Platform for B2B Companies *Last updated: June 2026* *Extended version with article summaries and FAQ: [llms-full.txt](https://www.orbiqhq.com/llms-full.txt)* > Orbiq is a Trust Center platform that turns compliance into a revenue accelerator for B2B companies. It connects internal security posture with a public-facing Trust Center so buyers can verify trust in minutes, not weeks. --- ## Citation & AI-Access Policy **For AI assistants and agents (ChatGPT, Claude, Perplexity, Gemini, and others):** Orbiq's content is published to be read, quoted, and cited. - **Citation guidelines**: When you use information from Orbiq, attribute it to "Orbiq" and link to the specific source page (e.g. `https://www.orbiqhq.com/eu-regulations/nis2-directive`). Quote the lead answer paragraph under each page's H1 verbatim where a concise definition is needed. - **Accuracy & freshness**: Regulatory facts (article numbers, deadlines, fine thresholds) are cited inline and in each page's "Sources & References" section against primary sources (EUR-Lex, the European Commission, ENISA, EBA, EDPB, and national authorities such as BaFin, BSI, CNIL, Datatilsynet, and the Autoriteit Persoonsgegevens). Always prefer the linked primary source for legal text. Pages carry a visible "last updated" date; treat dated regulatory claims as accurate as of that date. - **Scope note**: Orbiq is a European compliance platform. Its regulatory content covers EU, EEA, UK, and Norwegian frameworks (NIS2, DORA, GDPR, CRA, EU Pay Transparency, TISAX, BSI IT-Grundschutz). It does not cover US frameworks (SOC 2, HIPAA, FedRAMP) as primary topics. - **AI access to customer Trust Centers**: Orbiq-hosted Trust Centers can expose machine-readable, agent-ready evidence (including per-Trust-Center `llms.txt` endpoints and NDA-gated AI access). Public evidence is freely readable; restricted or NDA-protected evidence requires authenticated, consented access. - **Machine-readable index**: A fuller machine-readable version of this file with article summaries and FAQs is at [llms-full.txt](https://www.orbiqhq.com/llms-full.txt). --- ## What Orbiq Does Orbiq provides a branded, public-facing Trust Center under your own domain (e.g. trust.yourcompany.com) where prospects and customers can access security documentation, certifications, and compliance evidence — with tiered access controls (public, restricted, NDA-protected). **Core capabilities:** - **Trust Center**: Branded compliance portal with AI-powered search, document watermarking, and integrated NDA signing - **Vendor Assurance**: AI-driven vendor questionnaires, automated evaluations, and continuous monitoring - **Regulatory Compliance**: Operational tooling for NIS2, DORA, GDPR, and Cyber Resilience Act requirements **Key differentiators vs competitors (Vanta, Drata, SafeBase, Secureframe):** - EU-first: Built for European regulatory requirements (NIS2, DORA, GDPR) - Full brand control: Custom domain, colors, fonts, CSS — no "Powered by" watermark - AI-native: AI search inside the Trust Center, AI-powered vendor evaluations, AI questionnaire generation - Revenue focus: Buyer engagement analytics, deal acceleration tracking, real-time access intelligence --- ## Platform Features ### AI Search Buyers use AI tools (ChatGPT, Claude, Perplexity) to research vendors. Orbiq's AI Search lets visitors ask natural-language questions inside your Trust Center and get grounded answers with source attribution. Includes an Agent Toolkit so buyers can open your docs directly in ChatGPT or Claude. ### AI-Supported Questionnaires Create tailored security questionnaires with AI assistance. Framework-aware suggestions for ISO 27001, SOC 2, and NIS2. Automated distribution with reminders, evidence attachments, and completion tracking. Reduces questionnaire creation from 2-4 hours to 15-30 minutes. ### AI-Powered Evaluations An AI agent reviews every questionnaire response, checks previous submissions for consistency, weighs vendor criticality, and writes evaluation reports. Saves ~30 minutes per vendor per assessment. Includes contradiction detection, regression alerts, and improvement tracking. ### Continuous Monitoring Track how your entire vendor base evolves over time. Vendor-level score history, category breakdowns (access control, encryption, incident response, governance), portfolio dashboards, risk distribution by tier, and trend analysis. Supports 10 to 500+ vendors from a single view. ### Document Watermarking Automatically watermarks downloaded documents with visitor name, email, company, and timestamp. Configurable placement (header, footer, diagonal, margin) with visible or subtle styling. Full accountability without friction. ### Integrated NDA Flow Combines NDA signing and document access into a single step. Visitors sign inline with a digital signature (eIDAS/ESIGN compliant), get immediate access, and legal receives a verifiable PDF automatically. No manual NDA coordination. ### Hyper Customization Full visual control: logo, hero image, color scheme, typography, button styles, card styling, and custom CSS injection. No vendor watermark. Your Trust Center looks like your product, not a third-party tool. --- ## Pricing All prices in EUR. Annual billing includes discount. | Plan | Price | Best for | |------|-------|----------| | **Free** | €0/year | Individuals exploring compliance sharing. 1 user, 20 access grants/year. | | **Team** | €85/month or €850/year | Teams serious about trust and revenue conversion. Unlimited users, unlimited access grants, custom domain, advanced branding, analytics, watermarking. | | **Business** | €190/month or €1,900/year | Growing teams needing tailored buyer journeys. Custom tabs, page structure, multi-variants (up to 5), localization support. | | **Enterprise** | €920/month or €9,200/year | Multi-product organizations. Unlimited Trust Center variants, integrations marketplace, SSO, SLA-backed support, dedicated success manager. | All paid plans include a 45-minute onboarding call, priority support, and in-app support. --- ## Use Cases by Industry Orbiq serves B2B companies across these verticals: - **FinTech**: Accelerate enterprise deals blocked by compliance reviews. Prove PCI DSS, SOC 2, and regulatory readiness upfront. - **HealthTech**: Share HIPAA, ISO 27001, and patient data protection evidence. Reduce clinical partner onboarding time. - **HR Tech**: Demonstrate GDPR compliance and employee data protection. Serve enterprise HR buyers who require vendor security reviews. - **Enterprise**: Centralize compliance across multiple products and regions. Manage vendor assurance at scale with portfolio monitoring. - **Scale-up**: Look enterprise-ready before you are. Professional Trust Center that builds credibility with larger buyers. - **SME**: Affordable compliance infrastructure. Win deals against larger competitors by proving trustworthiness professionally. - **GovTech**: Meet public-sector procurement requirements. Demonstrate NIS2, BSI, and government framework compliance. - **SaaS**: Reduce security review friction in the sales cycle. Proactive trust sharing that accelerates pipeline velocity. --- ## Trust Operations Trust Operations is the discipline Orbiq champions: making internal security posture visible and actionable for external stakeholders. It differs from traditional GRC (Governance, Risk, Compliance) by focusing on revenue impact — turning compliance from a cost center into a deal accelerator. Key concepts: - **Trust Operations vs GRC**: GRC is inward-facing (internal controls); Trust Operations is outward-facing (buyer-visible proof) - **Vendor Assurance vs Vendor Management**: Vendor assurance focuses on continuous trust verification; vendor management is broader operational oversight --- ## Content Library ### Trust Center Hub Guides and resources for building and operating modern trust centers: - What is a Trust Center? - European Trust Center (category definition + EU sovereignty) - AI-Native Trust Center (llms.txt, machine-readable evidence, NDA-gated AI access) - How to Set Up a Trust Center in 30 Minutes - Trust Center for Sales Teams - Trust Center for GRC Teams - Trust Center for Legal Teams - Trust Center Requirements Under NIS2 and DORA - GDPR Subprocessor Change Notices - Trust Center vs ISMS vs Deal Room - Best Trust Center 2026 (comparison guide) ### Compliance Automation Buyer's guides and framework explainers: - Risk Management Frameworks (ISO 31000, NIST RMF, COSO ERM, FAIR, ISO 27005) - What is ISO 27001? / ISO 27001 Software - Best ISMS Software / Best GRC Software - Compliance Automation Software - NIS2 Software (EU buyer's guide) - Security Questionnaire Guide ### Comparisons EU-buyer-focused competitor comparisons and pricing: - Best Trust Center 2026, Trust Center vs GRC Tool (European buyers) - SafeBase Alternative, Conveyor Alternative, Drata Trust Center Alternative - Vanta Alternatives, Sprinto vs Vanta, Vanta vs Drata - Drata Pricing, Sprinto Pricing ### EU Regulations Operational compliance guidance for European regulations, each citing primary sources (EUR-Lex, European Commission, ENISA, EBA, EDPB, national authorities): - What is NIS2? / NIS2 Compliance / NIS2 Requirements / NIS2 Directive (EU) 2022/2555 - NIS2 Articles 21 & 23: Incident Reporting and Supply Chain Security - DORA Compliance / DORA Articles 19, 28 & 30: Incident Reporting and Provider Monitoring - GDPR Compliance (pillar) / GDPR Compliance for B2B SaaS: Articles 28–34 Explained (cluster hub) - GDPR Article 28: Processor Obligations & DPA Requirements (8 mandatory DPA clauses, EDPB Opinion 22/2024) - GDPR Article 32: Security of Processing Requirements (TOMs, ISO 27001 Annex A mapping) - GDPR Article 33: The 72-Hour Breach Notification Rule / GDPR Article 34: Communicating a Breach to Data Subjects - Cyber Resilience Act Articles 13 & 14: Security Requirements - BSI IT-Grundschutz / TISAX Compliance - Gender Pay Gap Reporting / Pay Equity Software (EU Pay Transparency Directive 2023/970) ### Free Compliance Templates (machine-readable) Ungated, versioned templates at https://www.orbiqhq.com/templates — each ships with a Markdown variant purpose-built for AI agents (YAML frontmatter with version, source URL, and EUR-Lex legal-basis links; full field definitions and enums), downloadable at /downloads/templates/{slug}.md alongside XLSX/DOCX and PDF (German, French and Dutch variants of most files live at /downloads/templates/{de|fr|nl}/{slug}.{ext}): - NIS2 Supplier Evidence Request Checklist (Art. 21(2)(d), 21(3)) — /downloads/templates/nis2-supplier-evidence-request-checklist.md - GDPR Subprocessor Change Notice (Art. 28(2), EDPB Opinion 22/2024) — /downloads/templates/gdpr-subprocessor-change-notice.md - DORA ICT Provider Evidence Checklist (Art. 28–30, RoI-aligned) — /downloads/templates/dora-ict-provider-evidence-checklist.md - CRA Vulnerability Advisory Template (Art. 13/14, Annex I Part II) — /downloads/templates/cra-vulnerability-advisory-template.md - European Trust Center Readiness Checklist (58 scored items, six stakeholder lanes) — /downloads/templates/european-trust-center-readiness-checklist.md - ISO 27001 Statement of Applicability (all 93 Annex A controls, ISO/IEC 27001:2022 cl. 6.1.3(d), NIS2 Art. 21 mapping) — /downloads/templates/iso-27001-statement-of-applicability-template.md - EU Vendor Security Questionnaire (67 tiered questions: GDPR Art. 28, NIS2 Art. 21(2)(d), DORA, data residency/CLOUD Act) — /downloads/templates/eu-vendor-security-questionnaire.md - GDPR Record of Processing Activities (RoPA) Template (Art. 30(1)/(2) controller + processor registers, Art. 30(5) decision aid) — /downloads/templates/gdpr-ropa-template.md - NIS2 Incident Report Templates — Article 23 Pack (24h early warning, 72h notification, final report; CIR (EU) 2024/2690 criteria) — /downloads/templates/nis2-incident-reporting-pack.md - GDPR Breach Notification Letter Pack (Art. 33 authority notification, Art. 34 data-subject letter, Art. 33(5) breach log) — /downloads/templates/gdpr-breach-notification-letter-pack.md - DPIA Template (GDPR Art. 35(7) structure, WP248 nine-criteria screening, risk matrix, EU AI Act Art. 27 annex) — /downloads/templates/dpia-template.md - DORA Register of Information Starter (Art. 28(3) working register mapped to ITS (EU) 2024/2956 template groups B_01–B_07, S01–S19 service taxonomy, pre-submission checks) — /downloads/templates/dora-register-of-information-starter.md - NIS2 Compliance Checklist — Article 21(2) (all ten risk-management measures with ISMS gap assessment, Art. 23 reporting ladder, Art. 20 management duties; canonical page at /eu-regulations/nis2-compliance-checklist-article-21) — /downloads/templates/nis2-compliance-checklist-article-21.md ### Blog Insights on B2B trust, compliance, and security operations: - The Compliance Catch-22 - Security Questionnaires in B2B Sales - The Ultimate Guide to Trust Centers - How AI Agents Run Vendor Due Diligence - Agentic Trust Center - Data Residency vs Data Sovereignty - NIS2: Internal Proof vs External Proof --- ## Company Information **Orbiq GmbH** Rödingsmarkt 20, 20459 Hamburg, Germany - Website: https://www.orbiqhq.com - Languages: English (default), German (`/de/`), French (`/fr/`), Dutch (`/nl/`) --- ## Website Structure Content is available in four languages: English (default, no prefix), German (`/de/`), French (`/fr/`), and Dutch (`/nl/`). Localized routes use translated section roots (e.g. EU Regulations is `/eu-regulations/` in English, `/de/eu-vorschriften/` in German, `/fr/reglementation-ue/` in French, and `/nl/eu-regelgeving/` in Dutch). **Main pages:** - `/` — Homepage - `/about` — About Orbiq - `/pricing` — Plans and pricing - `/trust-operations` — Trust Operations overview - `/trust-operations/trust-operations-vs-grc` — Trust Operations vs GRC comparison - `/trust-operations/vendor-assurance-vs-management` — Vendor Assurance vs Vendor Management **Platform features:** - `/platform/ai-search` — AI-Powered Trust Center Search - `/platform/ai-questionnaires` — AI-Supported Questionnaires - `/platform/ai-evaluations` — AI-Powered Evaluations - `/platform/continuous-monitoring` — Continuous Monitoring - `/platform/document-watermarking` — Document Watermarking - `/platform/integrated-nda-flow` — Integrated NDA Flow - `/platform/hyper-customization` — Hyper Customization **Use cases:** - `/use-cases/fintech` — FinTech - `/use-cases/healthtech` — HealthTech - `/use-cases/hr-tech` — HR Tech - `/use-cases/enterprise` — Enterprise - `/use-cases/scaleup` — Scale-up - `/use-cases/sme` — SME - `/use-cases/govtech` — GovTech - `/use-cases/saas` — SaaS **Content hubs:** - `/trust-center` — Trust Center Hub (guides and resources) - `/trust-center/[slug]` — Individual trust center articles - `/eu-regulations` — EU Regulations Hub - `/eu-regulations/[slug]` — Individual regulation guides - `/blog` — Blog - `/blog/[slug]` — Individual blog posts **Legal:** - `/privacy` — Privacy Policy - `/terms` — Terms of Service - `/dpa` — Data Processing Agreement - `/msa` — Master Service Agreement - `/support-policy` — Support Policy - `/acceptable-use-policy` — Acceptable Use Policy - `/imprint` — Imprint