Trust Center

Trust begins with clear boundaries, responsibilities, and evidence.

The WMT Trust Center explains how security, privacy, data protection, cloud operations, and reliability should be evaluated across products and services.

Trust domains

Three public summaries, one shared principle: verify the applicable context.

The pages identify important control areas without pretending that one generic statement can describe every product, deployment, customer, or agreement.

01

Security

Identity, authorization, application safeguards, infrastructure, secure delivery, operations, and incident responsibilities.

Explore Security
02

Privacy and Data Protection

Roles, lawful processing, data minimization, access, retention, requests, vendors, transfers, and contractual safeguards.

Explore Privacy and Data Protection
03

Cloud and Reliability

Deployment boundaries, environments, monitoring, maintenance, backup and recovery responsibilities, change, and continuity.

Explore Cloud and Reliability
Important: these public pages are explanatory summaries. They do not replace the signed agreement, data-processing terms, security schedule, architecture, deployment plan, service levels, support terms, or customer-specific controls.

Shared responsibility

Trust depends on the whole operating environment.

WMT controls only the parts of the solution and service assigned to WMT. Customers and third parties retain responsibilities for their users, decisions, systems, data, devices, networks, and connected services.

A useful assurance discussion identifies the product boundary, deployment model, data categories, users, identity source, integrations, hosting responsibilities, operational procedures, incident contacts, and evidence required for the intended use.

  1. Define the environment

    Product, version, deployment, infrastructure, interfaces, users, data, locations, and third parties.

  2. Assign controls

    Identify which controls are provided by WMT, the customer, hosting providers, identity providers, and other connected parties.

  3. Confirm evidence

    Determine the documents, configurations, tests, records, or responses needed for the customer’s evaluation.

  4. Maintain the model

    Manage approved change, access, incidents, patches, backups, support, review, and decommissioning responsibilities.

Evidence boundary

Public principles are not customer-specific assurance evidence.

WMT should provide the level of evidence appropriate to the relationship, request, confidentiality, product, service, deployment, and contractual stage.

01

Public evidence

Website summaries, policies, security contact details, product documentation, and general deployment information.

02

Evaluation evidence

Questionnaire responses, architecture discussions, control clarifications, data-flow review, and proposed contractual terms where applicable.

03

Project evidence

Approved designs, configurations, test results, migration reconciliation, acceptance records, operational procedures, and support routes.

04

Restricted evidence

Sensitive technical, operational, customer, or third-party information shared only through an approved and appropriately protected process.

Explore Trust

Choose the assurance area relevant to your decision.

Start with the public summary, then route customer-specific questions through the appropriate commercial, project, or support channel.

Controls

Security

Review identity, access, application, infrastructure, delivery, operational, and incident principles.

Explore Security

Data

Privacy and Data Protection

Review roles, processing, minimization, access, retention, requests, transfers, and vendor responsibilities.

Explore Privacy

Operations

Cloud and Reliability

Review deployment boundaries, monitoring, maintenance, backups, recovery, change, and continuity.

Explore Cloud and Reliability

Conversation

Request the right follow-up

Use Contact Sales for evaluation questions, Support for an existing environment, or Contact for general routing.

Contact SalesSupport

Questions

Frequently asked questions

Is the Trust Center a certification statement?

No. The public Trust Center explains principles and areas of responsibility. It does not claim a certification, audit result, control implementation, or contractual commitment unless explicitly stated in an authoritative document.

Are controls identical for every customer?

Not necessarily. Controls and responsibilities can vary by product, deployment model, hosting arrangement, integration, customer environment, and signed agreement.

Where are exact security and privacy commitments defined?

They are defined in the applicable proposal, agreement, data-processing terms, security schedule, architecture, deployment plan, support terms, and other approved project documentation.

Can WMT answer a security questionnaire?

Security and privacy questions can be routed through Contact Sales for an evaluation or through Support for an existing customer environment. The appropriate evidence depends on the request and relationship.

Does the Trust Center replace legal advice?

No. Customers should obtain their own legal, regulatory, security, and risk advice for their jurisdiction and intended use.

Assurance in context

Route the question according to the relationship and environment.

Evaluation questions, existing-customer concerns, and general enquiries require different context and evidence.