Why evidence matters
Claims are easy. Documented implementation is the difference.
A lot of small businesses take real cybersecurity steps. Customers and partners still have no simple way to see that readiness. Evidence is how Legacy Core tells the difference between a claim and a credential.
What you send
A paragraph vs. a package.
Reviewers do not want your opinion on security. They want something they can check, and a way to verify status without calling you.
What most owners send
To: client-security@example-corp.com
Subject: RE: Vendor security questionnaire
“We take security very seriously and use industry best practices. Our team is careful with client data and we can discuss further on a call if needed.”
No attachments. No verification link.
What a credentialed business sends
Harbor View Accounting [Example]
- documented-practices.pdf
- verification-link.txt
Reviewer checks the registry without calling you. Public status: Verified, Expired, Not Found.
Sample uses fictional data for illustration. Start Your Free Trust Audit
What evidence supports
Higher tiers, when the work is real.
Silver and Gold require evidence demonstrating that cybersecurity practices have progressed beyond awareness into documented implementation and ongoing readiness. Exact requirements vary by credential tier and business environment and are evaluated under the applicable Legacy Core Standards Release.
Identity and access
How the business controls who can reach accounts, systems, and client information. Silver and Gold look for documented implementation, not a claim that passwords exist.
Data protection
How the business handles, stores, and shares client and sensitive information. Higher tiers require evidence that those practices are in place, not only described.
Resilience
How the business can recover from disruption and keep operating. Gold expects a stronger showing that recovery is practiced, not only planned.
Security operations
Day-to-day protections around devices, email, and monitoring appropriate to the business. Gold is where ongoing visibility matters more than a one-time setup.
Governance
Written practices, incident readiness, vendor oversight, and team awareness. Evidence requirements vary by credential tier and business environment.
These are outcome areas, not a public checklist of acceptable files. What is required for a given business is determined under the applicable Legacy Core credential standard.
How Legacy Core handles evidence
Reviewed. Not published.
Evidence exists to support a credential decision. It is not a public exhibit.
Reviewed against the credential standard
Legacy Core credentials are subject to review under the applicable Legacy Core credential standard. Evidence requirements vary by credential tier and business environment.
Self-attestation is not enough
Silver and Gold cannot be earned by checking a box. They require evidence-based verification. Alliance Partners may help implement security. Legacy Core determines whether the credential has been earned.
Not shown on the Registry
Sensitive security evidence is not displayed in the Public Business Trust Registry. The Registry shows credential status and related public metadata, not uploaded files, screenshots, or review notes.
Supports higher tiers
Bronze establishes readiness. Silver verifies implementation only when evidence and appropriate review actually occur. Gold demonstrates continued maturity only when that higher bar is met.
Start with the Trust Gap
See where you stand. Then earn a credential people can check.
The Trust Audit is the free starting point. It does not issue a Trust Badge. Bronze establishes readiness. Silver and Gold come later, with evidence and review, when the business is actually there.
Start with the free Trust Audit to understand your Trust Gap before pursuing a reviewed Trust Badge.
Start Your Free Trust AuditSee what you could show today.
The Trust Audit is diagnostic only. It helps you understand the Trust Gap. The Trust Badge is earned through review.