| name | trust-signal-anatomy |
| description | Use when designing trust signals (logos, badges, testimonials, security marks, money-back guarantees). Covers what works, what's invisible, and what damages trust by trying too hard.
|
Trust Signal Anatomy
Trust signals reduce purchase anxiety. The wrong ones backfire.
Trust signals that work
| Signal | Best when |
|---|
| Named customer logos | 3+ recognizable + permission |
| Specific quote testimonial | Named human + outcome metric |
| Security badges (SOC 2, GDPR) | When you actually have them |
| "X years of [credential]" | When verifiable |
| Number of customers / fleets / etc. | When real and impressive |
| Money-back guarantee | When honored without friction |
| Open-source / public corpus | When code is real |
| Press logos (As Seen In) | When the press actually covered you |
Trust signals that don't
- Stock-photo testimonials with no name
- "Trusted by 1000+ companies" without showing logos
- Vague "10x faster" claims
- "Industry-leading" / "best-in-class" puffery
- Generic security icons (lock, shield) without specific certifications
- Customer counts that are clearly inflated
- "Free trial" without saying what's free
Where trust signals go
Best placements:
- Below hero — first impression
- Near pricing — highest anxiety moment
- Final CTA — last-mile reassurance
- Throughout, contextually — not all clustered
Don't put trust signals only at the bottom of the page.
Money-back guarantee
The strongest trust signal. Use only if:
- You'll actually honor it without friction
- The window is clearly stated (30 days standard)
- You make claiming easy (self-serve)
Anti-pattern: "30-day money-back guarantee*" with footnote of exclusions.
Specific quote testimonial
What makes one work:
- Name + role + company (and logo)
- One specific outcome ("cut audit prep from 3 weeks to 3 days")
- Sounds like the person actually said it
- Real photo, not stock
- Optional: link to case study
Security badges
- SOC 2 Type II → real, important for enterprise
- GDPR / CCPA compliant → verifiable
- HIPAA → if applicable to your space
- SSL / "Secure" → table stakes, doesn't add trust
- "Bank-level encryption" → buzzword, skeptics distrust
Common mistakes
- Stock-photo testimonials with first-name-only
- 12 customer logos none of which are recognizable
- Security icons without specific certifications
- "Trusted by 1000+ teams" without naming any
- Money-back with hidden exclusions
Where this fits in X3 Compass
X3 Compass uses: 6 inline trust checkmarks below hero CTA, "100 open-source compliance skills" corpus credibility (real, verifiable), 30-day money-back, E&O insured platform. Real customer logos pending.