User guide
Working with Trustbird. Screen by screen.
What you record in each part of Trustbird, why it protects your organisation and how to do it. The guide only describes what is built.
Looking for background on cyber risk and standards? Read the knowledge base.
Getting started
2 articles
Signing in and two-factor authentication
You sign in once at app.trustbird.com with your email address, your password and a code from your second factor. From there you open any workspace you belong to without signing in again.
Read more
Working in your own language
Trustbird works in English and Dutch. Each person chooses their own language on their Profile page, so a Dutch colleague and an English speaking auditor can use the same workspace side by side.
Read more
Today
6 articles
Due for review
Due for review lists every scheduled review in the workspace that falls due within the next 30 days or is overdue, across documents, risks, suppliers, measures and evidence. You complete a review here with a short note.
Read more
My documents to read
My documents to read lists the approved policies and procedures you have been asked to read. You open each one, read it and confirm that you did. Trustbird records who confirmed which version and when.
Read more
My tasks
My tasks lists every task assigned to you, with the soonest deadline first. You see what to do, why it matters and what it belongs to, and you complete a task straight from the list.
Read more
Tasks
Tasks holds every task in the workspace. You create a task with an action, a reason, an owner, who carries it out, a priority and a deadline, link it to a risk or measure, and complete it when it is done.
Read more
Today
Today is the first screen after you open a workspace. It shows four figures about your management system and one list of everything that needs your attention, with the soonest deadline first.
Read more
Today: what you see here and why
The Today group shows what is waiting for you: a short overview on the Today screen, your own tasks, every task in the workspace, what is due for review and the documents you have been asked to read.
Read more
Organisation
11 articles
Assets
Assets lists the devices, systems, applications, data stores and other things your organisation relies on, with an owner, a provider, how critical each one is and whether it holds personal or sensitive data.
Read more
Competency overview
The Competency overview shows, for every role in your organisation, which required competencies are covered and who is missing one or has let a qualification expire.
Read more
Interested parties
Interested parties records who, besides your own organisation, has a stake in how you handle information: customers, regulators, suppliers, employees and others. For each party you note what they expect and whether and how you deal with it.
Read more
Organisation profile
On Organisation you describe what your company does and for whom, where it works, how many people it employs, and which internal and external topics help or hinder it.
Read more
Organisation: what you record here and why
The Organisation group describes the company your management system covers: what you do, what is in scope, who works for you and in which role, what you rely on, and who expects something from you.
Read more
People
People lists everyone who works for your organisation, with their employment type and status. From here you also record their trainings and certificates and start the tasks for a colleague who joins or leaves.
Read more
Roles
Roles describes the functions in your organisation, such as security officer or lead developer: what each one is responsible for, what it may decide, who holds it and which competencies it requires.
Read more
Scope
On Scope you record what falls inside your management system, what you leave out and why, and where your responsibility ends and another party's begins. You then establish it as a fixed version.
Read more
Suppliers
Suppliers records who delivers what to your organisation, how critical they are, who owns the relationship, whether they process personal data and when you last reviewed them. You can also send them a questionnaire.
Read more
Task templates
Task templates holds the tasks Trustbird sets up when a colleague starts or leaves, or when you add a supplier or a system. The workspace owner adapts them to how your organisation works, or switches them off.
Read more
Teams
Teams groups people around a shared responsibility, such as development, operations or support. Each team has a name, a description, an owner and members drawn from People.
Read more
Risks
4 articles
Risk assessment method
This is where you agree how risks are weighed: the scales for likelihood and impact, where low turns into medium and medium into high, and up to which score a risk may be accepted through the normal process.
Read more
Risk overview
The Risk overview plots your risks on a matrix of likelihood and impact. Each cell shows how many risks sit there, so you can see at a glance where the heaviest ones are.
Read more
Risks
Risks is your risk register: what could go wrong, who keeps an eye on it, how big it is and what you are doing about it. A risk you reduce gets a treatment plan with actions and linked measures.
Read more
Risks: what you record here and why
The Risks group is where you agree how to weigh risks, record what could go wrong and what you are doing about it, and see at a glance where your biggest risks sit.
Read more
Measures and evidence
5 articles
Documents
Documents is where you manage your policies, procedures, work instructions, forms and records. Each document has versions: you write a draft, approve it, and ask colleagues to read and confirm it.
Read more
Evidence
Evidence is where you keep the files and links that show a measure works, such as an export of user accounts or the report of a restore test. One piece of evidence can support several measures and requirements at once.
Read more
Measures
Measures is where you describe what your organisation actually does to protect itself, such as daily backups or multi-factor sign-in. You link each measure to risks, requirements and evidence, and see at once whether it still works.
Read more
Measures and evidence: what you record here and why
The Measures and evidence group is where you describe what your organisation actually does to protect itself, keep the evidence that it works, plan reviews and manage your policies and procedures.
Read more
Reviews
Reviews is where you plan when someone takes a fresh look at a document, risk, supplier, measure or piece of evidence. When you complete a review, Trustbird schedules the next one a year later.
Read more
Improve
6 articles
Improve: what you record here and why
The Improve group is where you record what went wrong, what you learnt from it and whether you are making progress: incidents, nonconformities, internal audits, management reviews and objectives.
Read more
Incidents
This is where you report security incidents, from a lost laptop to a leaked password, and take them step by step to resolution, with a timeline of what happened.
Read more
Internal audits
This is where you plan your internal audits per year, record who carries them out and why they are independent, note the findings per requirement and download the report.
Read more
Management reviews
This is where you hold your management review: a fixed agenda of eight topics, with summaries Trustbird prepares, room for notes and decisions, follow-up tasks and a PDF report.
Read more
Nonconformities
This is where you record something that did not go as agreed and follow it through: the immediate correction, the root cause, the corrective actions and the check on whether they worked.
Read more
Objectives
This is where you set objectives for your information security: what you want to achieve, how you measure it, what target you aim for and by when. You record progress with a date and a measured value.
Read more
Prove
8 articles
Certificates
Certificates is where you record the certificates you hold for your adopted standards, with the certifying body, the certificate number and the validity period. Each one gets an audit cycle and a badge you can share.
Read more
Document requests
Document requests lists every request for a document you share on request. You approve or reject each one, and afterwards see who received which version, who decided and when the document was downloaded.
Read more
Documents on request
Documents on request lists the established documents customers can request through your trust page. They accept an NDA first and only receive a personal download link after someone in your workspace approves the request.
Read more
External audits
External audits lists the audits by your certifying body for every certificate, from surveillance to recertification. You record when each took place, the outcome and what the auditor found, with the deadline for your response.
Read more
Prove: what you show here and why
The Prove group is where you show others how you are doing: your standards and Statement of Applicability, your certificates and their audit cycle, and the trust page where customers see what you choose to share.
Read more
Standards
Standards shows the standard your workspace adopted and all its requirements. You decide per requirement whether it applies and how far you have got, establish the Statement of Applicability and export everything your auditor needs.
Read more
Trust page
On Trust page you switch your public trust page on or off, choose whether your valid certificates appear on it and write the introduction at the top.
Read more
Trust page content
Trust page content holds the short texts on your public trust page: summaries of your policies and descriptions of your security practices. Nothing appears publicly until the workspace owner establishes it.
Read more
Workspace
11 articles
AI connection
On AI connection the owner decides whether people in this workspace may connect their own AI assistant to Trustbird. The connection is off by default, and connecting an assistant is not possible yet.
Read more
Audit log
The Audit log shows who created, changed or deleted which record in this workspace, when, and the old and new values. Nobody can edit or remove an entry, not even an owner.
Read more
Billing
Billing is where an owner arranges the subscription: the plan and its price, paying monthly or yearly, the billing details your invoices are addressed to, your invoices, cancelling, and which version of the data processing agreement you accepted.
Read more
Export data
Export data lets an owner download everything the workspace holds as one ZIP file: all records as JSON, the text of every document version and the uploaded files. Trustbird builds it in the background and emails you when it is ready.
Read more
Import from Vanta
Import from Vanta lets an owner bring in the files exported from Vanta. Trustbird first shows what it would import without saving anything, and only starts the import once you confirm. Every import keeps its report.
Read more
Invite others
Invite others gives your workspace a personal referral link and code, ready-made texts to share them, and an overview of who signed up through you. A referral that qualifies earns you a month of credit.
Read more
Members and advisers
On Members you see who has access to this workspace and in which role: owner, member or advisor. An owner adds people, changes their role and decides which parts an external advisor may edit.
Read more
Onboarding
Onboarding shows the paid onboarding package of your workspace: the planning with its milestones week by week, who your onboarder is, and the two payments. An owner can choose a package here while one is available.
Read more
Switch workspace
Switch workspace lists the other workspaces you belong to and takes you to one of them without signing in again. It only appears when you are a member of more than one workspace.
Read more
Workspace settings
On Workspace settings an owner changes the address of the workspace: the part of the web address in front of the Trustbird domain. Links to the old address keep working.
Read more
Workspace: what you manage here and why
The Workspace group holds everything about Trustbird itself rather than your organisation: who has access and in which role, your subscription and invoices, the address of the workspace, importing from Vanta, exporting your data and the audit log.
Read more