Publish security audits
You should publish your (external) security audits that have been done. (with all vulnerabilities that are fixed, of course)
I'm talking about technical security audits (code audits/blackbox or whitebox-like etc.), not GDPR/privacy analyses/statements etc.
Again this improves trust and transparency.