So you have a Trust Center. Your human customers can hop in, grab your latest SOC 2 report, read your policies, get answers to their security questions, and move on with their risk assessment. Maybe you even have an AI agent running the show, helping visitors find what they need. Self-service. Easy.
But look at it from your customer's side. Vendor risk management is slow and manual, and they are under the same pressure you are to hand that work to an agent. So they try. The plan for the agent is simple.
- Get into your Trust Center
- Find and download the documents they need
- Analyze them against their own risk criteria and business context
- Ask your Trust Center agent follow-up questions to fill the gaps
- Write the report
Then run it 157 more times, once per vendor. Then re-run the whole thing weekly instead of annually, because continuous monitoring beats a once-a-year snapshot. You just agentified vendor risk! Unfortunately no, because it breaks at step one.
The useful documents are gated. Getting to them means logging in, waiting on a one-time code, or completing an OAuth flow. That is a wall only humans can climb. The agent hits it and stops. No documents, no answers, no assessment.
Trust Centers are built for humans, of course they are. But in 2026 we need something that is just as accessible for machines. To unlock programmatic, touchless trust, your Trust Center must serve agents and humans alike.
For it to work you need to be able to authenticate the agent on behalf of the person who sent it. Then every auto-approval rule you already built on visitor identity just works, and the agent runs step one through step five without anyone touching it.
You need a Trust Center built for the Age of AI. That is machine readable. In part because it’ll help you deliver a better customer experience, in part because it’s now becoming required, as outlined in the June update to FedRAMP.
That is what we mean by touchless. Agents talking to agents. We have been calling it the future of Customer Trust for a while now. It is the present.
Our customers have always pointed us towards touchless. As Marcin Baranowski, Senior Manager of Security Assurance and Insights at Zendesk, put it:
"A year ago, we were declining questionnaires just to stay afloat. Now we're exploring full automation. That's the kind of shift Conveyor made possible."
Introducing the first Trust Center built for agents

Now live - Our AI Connector built to serve humans and AI agent visitors to the Trust Center. Opt-in now and make your Trust Center machine readable today.
Here is what it looks like from your customer's side:
- Add the Conveyor visitor MCP server to Claude, ChatGPT, Gemini, or whatever agent they run.
- Authenticate once with their work email through OAuth or a one-time code.
- Prompt their agent to go visit a vendor's Trust Center.
- The agent finds and downloads the documents that visitor is entitled to, public or gated.
- It asks your Trust Center agent questions and gets answers back.
- It applies their own TPRM policy to everything it collects and writes the report.
- Then it moves to the next vendor through the same connector, and the next.
Because no human sits in the middle, it can also run on a schedule. Weekly vendor reviews instead of annual ones become a cron job.
Nothing about your access controls changes
Worth being precise here, because "programmatically accessible" tends to get read as "wide open." Or, very cumbersome per customer engagement. It is not.
Every access check runs exactly as it does for a human visitor, keyed to the visitor's authenticated email. Access groups, gated folders, NDA check, CRM-based auto-approval against Salesforce. All of it still applies. An agent whose human is not approved for a document does not get the document. It can request access, and you approve, deny, or gate behind an NDA the same way you always have. Watermarking works the same.
Logging works the same way. Sign-ins, documents accessed, and questions asked all get recorded in Conveyor and feed your per-customer audit trail and analytics. You can see which customers are showing up with agents and what they came for. If you want to analyze that, as a Conveyor admin the AI Connector will run the numbers for you with a simple prompt.
FedRAMP is now making this a requirement
FedRAMP's 2026 Certification Data Sharing rules define what makes a trust center FedRAMP-compatible. One of those rules is CDS-TRC-PAC, Programmatic Access: "Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.”
Now read that against a login wall and a one-time email code. A human-only Trust Center fails it outright, but an agentic Trust Center fits the bill.
The dates depend on your certification path. For FedRAMP 20x certifications, optional adoption opened July 4, 2026, and January 1, 2027 is the maintain date. For Rev5, January 1, 2027 is when you have to obtain, maintain lands August 1, 2027, and the grace period runs to your first independent assessment after that. If you sell to federal agencies, programmatic access stops being a good idea and starts being a line item inside the next few months.
How to turn it on

To make your own Trust Center agent accessible, go to Settings > Trust Center > Trust Center Agent and turn on Enable visitors to connect via MCP.
Full documentation lives at docs.conveyor.com/docs/visitor-ai-connector.
Your customers are already pointing agents at their vendors. The only question is whether yours answers the door.


-p-1600.avif)



