SME Trust Passport
Proof that travels. A rating anyone can verify.
The Trust Passport is a signed, shareable credential for your resilience rating. You send one live link; a lender, insurer or enterprise buyer verifies your current posture in seconds — no questionnaires, no email chains, no stale PDFs.
Issued to the pilot cohort from Q3 2026Pilot target
TrustQuant · SME Trust Passport
IllustrativeAlder & Wren Manufacturing Ltd.
Illustrative organisation · UK SME
82
Resilience Rating · verified evidence
Decorative · not scannable
- Issued
- 28 Jun 2026
- Expires
- 26 Sep 2026
- Passport ID
- TQP-2026-0842
- Verify code
- K7QF-2M9X-D318
Flips to show exactly what a verifier sees
Try it — “Verify this passport” flips the card to the verifier’s exact view.
One link instead of every questionnaire
Today, proving cyber posture means re-answering the same questions for every lender, insurer and enterprise buyer — then doing it all again at renewal. The passport replaces that loop with a single verifiable source.
You share one link
Issue a passport from your dashboard and drop the link into a tender response, a renewal form or an email signature. No attachment, no export, nothing to keep up to date.
They verify in seconds
The verifier opens the link and sees your current rating, its band, the validity window and a signature check. No account, no call, no questionnaire to send back.
The proof stays current
The passport resolves against your live assessment, not a snapshot. When your rating refreshes, the passport does too — and if the evidence behind it goes stale, verification says so.
Who asks — and what they see
Different verifiers ask at different moments, but every one of them sees the same bounded disclosure: your rating and band, the validity window, the signature and revocation state, and a summary across the published factor groups.
What they never see: raw telemetry, hostnames or IPs, vulnerability specifics, or any personal data. The passport answers “can this organisation be trusted?” without handing over the evidence room.
Commercial lenders
During underwriting and annual reviews
Chasing cyber questionnaires alongside the credit file — the passport gives a verified, current resilience signal in one check.
Cyber insurers
At quote and at renewal
Proposal-form self-attestation. Underwriters verify the rating directly instead of trusting a box the applicant ticked months earlier.
Enterprise procurement
At supplier onboarding and periodic re-assessment
The vendor security spreadsheet. One verification stands in for hundreds of near-identical questions answered from memory.
MSPs, on behalf of clients
Whenever a managed client is asked to prove posture
Bespoke evidence packs assembled per request — the client's passport answers the question the same way every time.
Revocation & expiry
A credential with a lifecycle, not a PDF with a date
A report is true the day it is exported and unverifiable ever after. A passport is checkable for exactly as long as it deserves to be — and fails closed the moment it doesn't.
Issued
Created from a completed assessment and signed by TrustQuant. Every passport carries its issue date, expiry date and a verification code — the signature binds all three.
Refreshed
While your infrastructure stays connected, the passport tracks your live rating. A verifier always sees today's posture — improvements show up exactly as fast as regressions.
Expired
Each passport has a fixed validity window. Past expiry, verification fails closed — it reports “expired” rather than showing yesterday's numbers with today's date.
Revoked
You can withdraw a passport at any time, and disconnecting your infrastructure revokes it automatically. A revoked passport fails verification immediately, everywhere it was ever shared.
For the pilot cohort we are targeting a 90-day validity window with continuous refresh while connected, and a verification log so you can see when your passport was checked. Final windows are confirmed with pilot participants.
Pilot targetStraight answers
The questions verifiers and passport holders ask first.
What does a verifier need to check a passport?
Only the link or the verification code printed on the passport. Verification is read-only and requires no TrustQuant account, so a lender or procurement lead can check it in the middle of their existing process.
What if my rating changes after I share it?
The passport shows your current rating, not the one you had when you shared the link. That cuts both ways by design: a drop is visible, and so is every improvement — which is exactly why a verifier can trust it more than a PDF.
Can a passport be forged or edited?
Verification resolves against TrustQuant, not against the document in front of the verifier. A forwarded screenshot or an edited PDF proves nothing; only the live signature check does. If the signature, validity window or revocation state fails, the verifier is told so plainly.
Who controls what is shared?
You do. You issue each passport, you can revoke it at any moment, and the disclosure boundary is fixed: rating, band, validity and a factor-group summary. Raw telemetry, hostnames, vulnerability detail and personal data never leave your assessment.
Carry proof, not paperwork
Pilot cohort organisations will be the first to hold a Trust Passport — and to stop answering the same questionnaire twice.