Skip to content

SME Trust Passport

Proof that travels. A rating anyone can verify.

The Trust Passport is a signed, shareable credential for your resilience rating. You send one live link; a lender, insurer or enterprise buyer verifies your current posture in seconds — no questionnaires, no email chains, no stale PDFs.

Issued to the pilot cohort from Q3 2026Pilot target

TrustQuant · SME Trust Passport

Illustrative

Alder & Wren Manufacturing Ltd.

Illustrative organisation · UK SME

82

Resilient · 80–100

Resilience Rating · verified evidence

Decorative · not scannable

Issued
28 Jun 2026
Expires
26 Sep 2026
Passport ID
TQP-2026-0842
Verify code
K7QF-2M9X-D318

Flips to show exactly what a verifier sees

Try it — “Verify this passport” flips the card to the verifier’s exact view.

One link instead of every questionnaire

Today, proving cyber posture means re-answering the same questions for every lender, insurer and enterprise buyer — then doing it all again at renewal. The passport replaces that loop with a single verifiable source.

01

You share one link

Issue a passport from your dashboard and drop the link into a tender response, a renewal form or an email signature. No attachment, no export, nothing to keep up to date.

02

They verify in seconds

The verifier opens the link and sees your current rating, its band, the validity window and a signature check. No account, no call, no questionnaire to send back.

03

The proof stays current

The passport resolves against your live assessment, not a snapshot. When your rating refreshes, the passport does too — and if the evidence behind it goes stale, verification says so.

Who asks — and what they see

Different verifiers ask at different moments, but every one of them sees the same bounded disclosure: your rating and band, the validity window, the signature and revocation state, and a summary across the published factor groups.

What they never see: raw telemetry, hostnames or IPs, vulnerability specifics, or any personal data. The passport answers “can this organisation be trusted?” without handing over the evidence room.

Commercial lenders

During underwriting and annual reviews

Chasing cyber questionnaires alongside the credit file — the passport gives a verified, current resilience signal in one check.

Cyber insurers

At quote and at renewal

Proposal-form self-attestation. Underwriters verify the rating directly instead of trusting a box the applicant ticked months earlier.

Enterprise procurement

At supplier onboarding and periodic re-assessment

The vendor security spreadsheet. One verification stands in for hundreds of near-identical questions answered from memory.

MSPs, on behalf of clients

Whenever a managed client is asked to prove posture

Bespoke evidence packs assembled per request — the client's passport answers the question the same way every time.

Revocation & expiry

A credential with a lifecycle, not a PDF with a date

A report is true the day it is exported and unverifiable ever after. A passport is checkable for exactly as long as it deserves to be — and fails closed the moment it doesn't.

State 1 / 4

Issued

Created from a completed assessment and signed by TrustQuant. Every passport carries its issue date, expiry date and a verification code — the signature binds all three.

State 2 / 4

Refreshed

While your infrastructure stays connected, the passport tracks your live rating. A verifier always sees today's posture — improvements show up exactly as fast as regressions.

State 3 / 4

Expired

Each passport has a fixed validity window. Past expiry, verification fails closed — it reports “expired” rather than showing yesterday's numbers with today's date.

State 4 / 4

Revoked

You can withdraw a passport at any time, and disconnecting your infrastructure revokes it automatically. A revoked passport fails verification immediately, everywhere it was ever shared.

For the pilot cohort we are targeting a 90-day validity window with continuous refresh while connected, and a verification log so you can see when your passport was checked. Final windows are confirmed with pilot participants.

Pilot target

Straight answers

The questions verifiers and passport holders ask first.

What does a verifier need to check a passport?

Only the link or the verification code printed on the passport. Verification is read-only and requires no TrustQuant account, so a lender or procurement lead can check it in the middle of their existing process.

What if my rating changes after I share it?

The passport shows your current rating, not the one you had when you shared the link. That cuts both ways by design: a drop is visible, and so is every improvement — which is exactly why a verifier can trust it more than a PDF.

Can a passport be forged or edited?

Verification resolves against TrustQuant, not against the document in front of the verifier. A forwarded screenshot or an edited PDF proves nothing; only the live signature check does. If the signature, validity window or revocation state fails, the verifier is told so plainly.

Who controls what is shared?

You do. You issue each passport, you can revoke it at any moment, and the disclosure boundary is fixed: rating, band, validity and a factor-group summary. Raw telemetry, hostnames, vulnerability detail and personal data never leave your assessment.

Carry proof, not paperwork

Pilot cohort organisations will be the first to hold a Trust Passport — and to stop answering the same questionnaire twice.