“Add trust signals” is common advice and mostly useless, because it treats every signal as interchangeable. They are not. Some remove a specific blocker from a live deal. Most are decoration that a buyer's eye passes over.
The difference is whether the signal answers a question somebody was actually going to ask.
The test
For any proposed trust signal, ask: what specific hesitation does this remove, and who has it?
A subprocessor list removes a specific hesitation held by a specific person — whoever reviews vendors for data handling. A row of unexplained badges removes nothing, because no reader was wondering about it.
If you cannot name the hesitation and the person, the signal is decoration. That does not make it worthless, but it should not be prioritised over something that unblocks a deal.
Signals that reliably unblock
Ranked by how often they remove a real objection:
- A specific, dated privacy policy. Not boilerplate — a policy that names what you collect and what you do with it. Reviewed in nearly every B2B deal above trivial size.
- A current subprocessor list. Now asked for almost universally and prepared for almost never. Cheap to publish, and its absence stalls deals.
- A security page that answers the standard questions. Data location, encryption, retention, incident notification. This can remove the questionnaire entirely for smaller deals — see what to have ready before it's asked.
- Named humans with real roles. Removes the “is this a real company” hesitation, which is more common than most founders believe.
- A stated pricing model. Even without numbers. Hidden pricing is read as expensive, negotiable or undecided, and all three cost you.
- One detailed customer story. Named customer, specific situation, specific outcome. Outperforms a wall of logos by a wide margin.
- A registered legal entity. Small detail, disproportionate effect on anyone who has been burned.
Signals that mostly decorate
Not harmful, but rarely worth prioritising:
- Logo walls without context. Every reader knows a logo can mean one free trial three years ago.
- Anonymous testimonials. “— VP of Engineering, Fortune 500” is read as invented.
- Award badges from organisations the reader has never heard of.
- Unexplained compliance icons. A certification logo with no page behind it and no scope stated. If the reader has to guess whether it is real, it is not doing its job.
- Round-number claims. “10,000+ users” is treated as marketing; “11,400 users” is treated as a fact.
Signals that actively hurt
Worth auditing for, because they cost more than they return:
- Stale dates. A copyright notice showing a past year, a blog dormant for a year, a team page listing people who left. Each says the company may not be operating.
- Policies that contradict the product. Terms describing a service you no longer sell suggests nobody is reading them, which invites the question of what else nobody is reading.
- Overclaimed compliance. Implying a certification you do not hold is a serious problem, not a marketing liberty. A buyer who checks and finds it untrue is gone permanently, and may say so publicly.
- A contact route that does not work. An unmonitored address is worse than no address.
The severity question
When auditing gaps, the instinct is to treat everything missing as urgent. That produces a list nobody acts on and, worse, misallocates the budget.
Most gaps fall into one of three tiers: things that block deals now, things a buyer will ask about eventually, and things that would be nice. A missing subprocessor list is the first. An absent DPA template is usually the second — “available on request” is a perfectly acceptable answer. A trust centre with a slick design is the third.
Treating a tier-three item as a crisis is how trust work gets a reputation for consuming budget without moving anything. We go into the ranking in ranking security gaps.
Where to start
If you are doing this from nothing, the order that recovers the most deal friction per hour is: fix any stale date on the site, publish a subprocessor list, put names on the About page, state the pricing model, and write one real customer story.
That is a day of work and it removes more hesitation than a redesign. See also what buyers check before they trust your site.
Our Trust & Security Audit reads a site the way a cautious buyer would and ranks each gap by whether it actually blocks a deal, rather than presenting every absence as equally urgent.