Trust / Security Stack
Trust & security center pages with WebPage context, Organization identity, FAQs, and breadcrumb navigation.
When to use this stack
- Trust/security center pages that outline policies, certifications, and contacts
- Security/compliance hubs that link to SOC 2/ISO, pen tests, and incident response
- Pages where FAQs address data handling, encryption, and responsible disclosure
What is included
Declares the page as the trust/security hub.
Anchors the brand identity, contact, and logo for trust context.
Answers top trust/compliance questions.
Provides navigation context within the security/compliance section.
Properties across the bundle
Nested properties keep their parent path, such as offers.priceCurrency. Only publish values that match visible page content.
Required properties
- description
- itemListElement[].name
- logo
- mainEntity[].@type=Question
- mainEntity[].acceptedAnswer.text
- name
- url
Recommended properties
- contactPoint.contactType
- contactPoint.telephone
- dateModified
- inLanguage
- itemListElement[].item
- mainEntity[].acceptedAnswer.text
- mainEntity[].author.name
- mainEntity[].name
- sameAs
Combined JSON-LD
Paste this as one script tag, then replace every example value with data from the live page.
[
{
"@context": "https://schema.org",
"@type": "WebPage",
"@id": "https://www.example.com/trust#page",
"name": "Trust & Security — Example Corp",
"description": "Security, privacy, compliance, and incident response at Example Corp.",
"url": "https://www.example.com/trust",
"inLanguage": "en",
"dateModified": "2025-02-10"
},
{
"@context": "https://schema.org",
"@type": "Organization",
"@id": "https://www.example.com/#org",
"name": "Example Corp",
"url": "https://www.example.com",
"logo": "https://www.example.com/assets/logo.svg",
"sameAs": [
"https://www.linkedin.com/company/example-corp"
],
"contactPoint": [
{
"@type": "ContactPoint",
"telephone": "+1-415-555-0100",
"contactType": "security"
}
]
},
{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Do you have SOC 2 or ISO certifications?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Yes. We maintain SOC 2 Type II and ISO 27001. Request the latest reports from our security team."
}
},
{
"@type": "Question",
"name": "How do you handle encryption?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys are managed via a hardened KMS."
}
},
{
"@type": "Question",
"name": "How do I report a vulnerability?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Email security@example.com with reproduction steps. We follow a 48-hour acknowledgement SLA and prioritize remediation based on severity."
}
}
]
},
{
"@context": "https://schema.org",
"@type": "BreadcrumbList",
"itemListElement": [
{ "@type": "ListItem", "position": 1, "name": "Home", "item": "https://www.example.com" },
{ "@type": "ListItem", "position": 2, "name": "Trust & Security", "item": "https://www.example.com/trust" }
]
}
]Implement and verify
- 01
Start with the live page
Confirm titles, prices, availability, policies, and visible FAQ content before generating markup.
- 02
Add one JSON-LD script
Use the combined example as a template in the document head or before the closing body tag.
- 03
Complete regional details
Fill shipping destinations and timing for every region the page actually serves.
- 04
Link the return policy
Use a stable MerchantReturnPolicy URL and keep its terms synchronized with the page.
- 05
Match visible answers
Add only FAQs that users can read on the same page, with identical answers.
- 06
Validate after changes
Run Rich Results Test after implementation and whenever price, availability, or policy data changes.
Common errors and fixes
- Missing currency or availability
Use ISO currency codes and complete schema.org availability URLs in Offer data.
- Incomplete shipping details
Include shippingDestination.addressCountry and deliveryTime.transitTime with units.
- Return policy is not connected
Reference MerchantReturnPolicy from the Offer and provide a stable public policy URL.
- FAQ answers differ from the page
Keep structured FAQ answers identical to visible answers.
Stack FAQs
Should I include every certification?
List only certifications you actually hold and keep report links gated if needed; ensure on-page content matches the JSON-LD.
Where do I link incident status?
Link your status page from the WebPage body and FAQ answers; keep URLs stable and use https.