This internal article explains how Support should respond when a customer requests vendor management, compliance, security, business continuity, disaster recovery, penetration testing, or audit documentation, such as a SOC 2 Type II report.
Overview
DigiCert and Vercara maintain separate Trust Center pages. These pages have some overlapping corporate security language, but they are not duplicates and should not be treated as interchangeable.
The DigiCert Trust Center is used for DigiCert corporate and DigiCert product due diligence. The Vercara Trust Center is used for Vercara and Ultra service-specific due diligence, including UltraDNS, UltraDDoS, UltraWAF, UltraSecurity, and Vercara business continuity or disaster recovery documentation.
Important Access Restriction
These reports are for customers only and must not be shared publicly.
Before providing access instructions, confirm that the requester is a customer.
Which Trust Center to Use
DigiCert Trust Center
Use the DigiCert Trust Center when the customer is requesting DigiCert corporate or DigiCert product documentation.
Examples include:
- DigiCert corporate security posture
- DigiCert SOC 2 or SOC 3 reports
- DigiCert legal, insurance, W-9, supplier setup, or company information
- CertCentral documentation
- DigiCert ONE documentation
- MPKI documentation
- DigiCert global accreditations or corporate policy summaries
DigiCert Trust Center:
https://digicert.hypercomply.io/
Vercara Trust Center
Use the Vercara Trust Center when the customer is requesting Vercara or Ultra service-specific documentation.
Examples include:
- UltraDNS security documentation
- UltraDNS SOC or DNS-specific SOC documentation
- UltraDNS penetration testing documentation
- UltraDDoS or UltraWAF security documentation
- UltraSecurity documentation
- Vercara-specific policy documents
- Vercara business continuity, disaster recovery, or business impact analysis documentation
- Vercara Protect documentation
Vercara Trust Center:
https://4adf5555927742bf6bb0e0c1f47146aa.hypercomply.io/
Required Handling
- Confirm that the requester is a customer.
- Determine whether the request is for DigiCert corporate/product documentation or Vercara/Ultra service-specific documentation.
- Direct the customer to the applicable Trust Center:
- DigiCert corporate or DigiCert product documentation:
DigiCert Trust Center - Vercara, UltraDNS, UltraDDoS, UltraWAF, UltraSecurity, or Vercara business continuity documentation:
Vercara Trust Center
- DigiCert corporate or DigiCert product documentation:
- Advise the customer to select Request Access in the top-right corner of the applicable Trust Center page.
- Advise the customer to submit a request for the files they need.
- If the customer requests both DigiCert corporate documentation and Vercara/Ultra service-specific documentation, provide both Trust Center links and explain that the document scope differs.
- If the requester cannot access the Trust Center, is not approved, or there is uncertainty about whether the report can be shared, contact the customer's Account Manager for assistance.
- If the customer does not know who their Account Manager is, contact one of the following internal contacts:
- Channing VanHorn
- Sean Kelly
CVE and Vulnerability Questions
A request asking whether a specific CVE or vulnerability affects a DigiCert, Vercara, or Ultra service is not handled solely as a vendor management report request. Follow the workflow documented in the Vulnerability verification requests article.
Customers may request the available SOC 2 Type II report, bridge letter, or other security documentation through the applicable Trust Center. Requesting these reports is not a prerequisite for submitting a CVE or vulnerability question.
Suggested Customer Response - DigiCert Documentation
The requested DigiCert vendor management, compliance, and security files are available through the DigiCert Trust Center.
Please use the Trust Center link below and select Request Access in the top-right corner of the page. After you submit the request, access to the applicable files can be reviewed and provided through the Trust Center.
Suggested Customer Response - Vercara or Ultra Service Documentation
The requested Vercara and Ultra service-specific vendor management, compliance, and security files are available through the Vercara Trust Center.
Please use the Trust Center link below and select Request Access in the top-right corner of the page. After you submit the request, access to the applicable files can be reviewed and provided through the Trust Center.
Suggested Customer Response - Both DigiCert and Vercara Scope
DigiCert maintains a broader corporate Trust Center for DigiCert company-level and DigiCert product documentation. Vercara, a DigiCert company, maintains a separate Trust Center for Vercara-specific services such as UltraDNS, UltraDDoS, UltraWAF, UltraSecurity, and related Vercara business continuity, SOC, and penetration testing artifacts.
Some corporate security language overlaps because Vercara is part of DigiCert, but the document scope differs. Please use the applicable Trust Center links below and select Request Access in the top-right corner of each page for the files you need.
DigiCert Trust Center:
https://digicert.hypercomply.io/
Vercara Trust Center:
https://4adf5555927742bf6bb0e0c1f47146aa.hypercomply.io/
Important Notes
- Do not tell customers that the DigiCert Trust Center and Vercara Trust Center are duplicates. They have overlapping information, but the document scope differs.
- Do not attach or directly send customer security reports unless the sharing process has been approved through the appropriate internal channel.
- Do not provide these reports to non-customers.
- Contact the customer's Account Manager when access approval or report-sharing authorization is unclear.
- Use the Vercara Trust Center for UltraDNS, UltraDDoS, UltraWAF, UltraSecurity, and Vercara-specific documentation unless the customer specifically requests DigiCert corporate or DigiCert product documentation.
- Use the DigiCert Trust Center for DigiCert corporate due diligence, DigiCert legal/vendor documentation, CertCentral, DigiCert ONE, MPKI, and DigiCert-specific SOC or accreditation documentation.
- Use the Vulnerability verification requests article for requests asking whether a specific CVE or vulnerability affects a service.