---
title: "What's new at Trooth: the changelog - Trooth"
description: "What actually shipped on Trooth, dated. Every change that affects what is witnessed, confirmed or published, with who is affected, whether anyone must act and by when. Filter by area, type and month, and follow by feed."
canonical_url: "https://trooth.co/changelog"
markdown_url: "https://trooth.co/changelog.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

1. [Home](https://trooth.co/)
2. Changelog

Changelog

# What's new at Trooth

Changes that affect what Trooth witnesses, confirms or publishes, recorded when they happen, not described later as marketing. Each one says who is affected, whether anyone has to act, and by when.

Subscribe to updates [RSS](https://trooth.co/changelog/rss.xml)

## Upcoming deadlines

- [Sep 28, 2026Shared webhook signing key retired](https://trooth.co/changelog/2026-09-26-webhook-signatures-v2)
- [Oct 5, 2026Unproven webhook endpoints stop receiving; shared-key deliveries end](https://trooth.co/changelog/2026-09-26-webhook-signatures-v2)
- [Mar 1, 2027Profile contract version 1 withdrawn](https://trooth.co/changelog/2026-09-26-counts-from-signed-statement)

Search the changelog

AreaMonthNeeds action only

17 changes

1. Sep 27, 2026
   Methodology
## [The two Standards and the About page, rebuilt as references](https://trooth.co/changelog/2026-09-27-standards-and-about-page-as-references)

   The Trooth Standard and the Buyer Review Standard are rebuilt as references: each shows its version, who maintains it and its revision history, and every requirement or item says what it asks and what it does not establish. Requirement 08 is retitled to say what its checks cover. The About page names the founder and pairs each commitment with its evidence.
   **Availability**
   Available. Public. No account needed.
   **Impact**
   No action required
   [Read the change](https://trooth.co/changelog/2026-09-27-standards-and-about-page-as-references) #
2. Sep 27, 2026
   New
## [A public feedback board, and a comparison you can start with any two companies](https://trooth.co/changelog/2026-09-27-feedback-board-and-comparison)

   Feedback is now a public board: search what others asked, vote, comment, and follow each request to the change that shipped it. Any two companies can be compared, up to four, on their published records.
   **Availability**
   Available. Public. No account needed. Every request is stored on the board and also reaches a person by email with its reference.
   **Impact**
   No action required
   [Read the change](https://trooth.co/changelog/2026-09-27-feedback-board-and-comparison) #
3. Sep 27, 2026
   Improvement
## [A developer reference you can build from, and a changelog you can follow](https://trooth.co/changelog/2026-09-27-developer-reference-and-changelog)

   The developer reference is rebuilt as a two-column reference with a quickstart, limits stated as numbers, and one entry per endpoint. The changelog can be searched, filtered, linked to and followed by feed.
   **Availability**
   Available. Public. No account needed.
   **Impact**
   No action required
   [Read the change](https://trooth.co/changelog/2026-09-27-developer-reference-and-changelog) #
4. Sep 27, 2026
   Methodology
## [The methodology is versioned, with an example profile you can inspect](https://trooth.co/changelog/2026-09-27-methodology-versioned)

   The methodology page now carries a version, an effective date and a change log, defines all ten evidence labels, and has an invented example profile you can inspect without an account.
   **Availability**
   Available. Public. No account needed.
   **Impact**
   No action required
   [Read the change](https://trooth.co/changelog/2026-09-27-methodology-versioned) #
5. Sep 26, 2026
   New
## [A bill of materials for every Worker, and Trooth's own record corrected](https://trooth.co/changelog/2026-09-26-worker-bills-of-materials)

   Every Cloudflare Worker behind api.trooth.co now has a public software bill of materials, and two claims on Trooth's own Trust Profile were corrected to match its policies.
   **Availability**
   Available. Public. No account needed.
   **Impact**
   No action required
   [Read the change](https://trooth.co/changelog/2026-09-26-worker-bills-of-materials) #
6. Sep 26, 2026
   Improvement
## [Counts on a profile now come from the signed witness statement](https://trooth.co/changelog/2026-09-26-counts-from-signed-statement)

   Check counts on a Trust Profile, in the profile API and from the MCP server now come from the signed witness statement. Profile contract 1 is withdrawn on 2027-03-01.
   **Availability**
   Available. The Trust Profile read in the API and the MCP server. No key.
   **Impact**
   Action required by Mar 1, 2027
   [Read the change](https://trooth.co/changelog/2026-09-26-counts-from-signed-statement) #
7. Sep 26, 2026
   Improvement
## [Trooth command-line tool 0.5.0: lint reports what it could not read](https://trooth.co/changelog/2026-09-26-cli-0-5-0)

   Version 0.5.0 of the trooth command-line tool parses the files it lints, reports what it could not read, and exits with code 4 when a file cannot be parsed.
   **Availability**
   Available. npm and GitHub. No account.
   **Impact**
   Action required
   [Read the change](https://trooth.co/changelog/2026-09-26-cli-0-5-0) #
8. Sep 26, 2026
   Improvement
## [Disputes are handled privately; framework rollups and the old badge are retired](https://trooth.co/changelog/2026-09-26-disputes-private-rollups-retired)

   Disputes are visible only to the company concerned and to Trooth. Framework rollups are retired from the public mesh and comparisons, and badge 1.0.0 can be pinned.
   **Availability**
   Available. Public. No account needed.
   **Impact**
   Action required
   [Read the change](https://trooth.co/changelog/2026-09-26-disputes-private-rollups-retired) #
9. Sep 26, 2026
   Security
## [Webhook signatures: shared key retired, unproven endpoints stop](https://trooth.co/changelog/2026-09-26-webhook-signatures-v2)

   Webhooks are signed per endpoint with a version 2 signature. The shared signing key is retired on 2026-09-28, and endpoints that have not proven ownership stop receiving on 2026-10-05.
   **Availability**
   Available. Company workspaces with webhook endpoints.
   **Impact**
   Action required by Oct 5, 2026
   [Read the change](https://trooth.co/changelog/2026-09-26-webhook-signatures-v2) #
10. Sep 26, 2026
    Improvement
## [Legal and trust documents revised to match the product](https://trooth.co/changelog/2026-09-26-legal-documents-revised)

    The Acceptable Use Policy, the API terms and the connector, privacy, retention, corrections and versioning documents were revised to match what the product does.
    **Availability**
    Available. Public.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-09-26-legal-documents-revised) #
11. Sep 4, 2026
    Deprecation
## [The 0-100 figure is deleted](https://trooth.co/changelog/2026-09-04-single-figure-deleted)

    Trooth no longer computes, stores or publishes a single number summarizing a company. The figure and everything that displayed it are deleted.
    **Availability**
    Available. Everywhere Trooth published the figure.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-09-04-single-figure-deleted) #
12. Aug 2, 2026
    New
## [Launch: the Trooth Network is open](https://trooth.co/changelog/2026-08-02-network-launch)

    The Trooth Network opened: any company can claim a free profile and be witnessed, and any buyer can look up a vendor before a call.
    **Availability**
    Available. Public. Company profiles are free.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-08-02-network-launch) #
13. Jul 25, 2026
    New
## [Register views, severity-true sorting, CSV evidence exports](https://trooth.co/changelog/2026-07-25-register-views)

    Every register in the company workspace shares one table system with saved views, severity-true sorting and exports that match what is displayed.
    **Availability**
    Available. Company workspaces.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-07-25-register-views) #
14. Jul 24, 2026
    New
## [Model Context Protocol server, incident ledger, ML-BOM export, Guard policy center](https://trooth.co/changelog/2026-07-24-mcp-server-incident-ledger)

    The public trust layer became queryable over the Model Context Protocol, and a public append-only incident ledger opened with this changelog.
    **Availability**
    Available. Public. No key.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-07-24-mcp-server-incident-ledger) #
15. Jul 24, 2026
    New
## [API keys, live outside-in reads, dispute path, /verify](https://trooth.co/changelog/2026-07-24-api-keys-live-reads)

    Revocable workspace API keys, live outside-in reads on unclaimed profiles, a dispute path for anything Trooth publishes, and /verify.
    **Availability**
    Available. API keys: company workspaces. Everything else: public.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-07-24-api-keys-live-reads) #
16. Jul 24, 2026
    New
## [People, Access Reviews, policy acceptance, Auditor Portal, vendor-network record](https://trooth.co/changelog/2026-07-24-people-access-reviews)

    Personnel lifecycle, access review campaigns, typed-name policy acceptance, read-only auditor portals, and each vendor's live witnessed record in the vendor register.
    **Availability**
    Available. Company workspaces.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-07-24-people-access-reviews) #
17. Jul 23, 2026
    New
## [Trooth Network on real directory data](https://trooth.co/changelog/2026-07-23-network-on-directory-data)

    The public Network reads the live directory and signed readings, so nothing on a Trust Profile is entered by hand.
    **Availability**
    Available. Public.
    **Impact**
    Action not assessed
    [Read the change](https://trooth.co/changelog/2026-07-23-network-on-directory-data) #

## Three histories, kept apart

This page is the product's history. Two others are kept separately, because they answer different questions and one of them is not public.

- ProductWhat Trooth shipped, changed or retired. This page, public.
- [MethodologyHow facts are labeled, dated and settled, with a version and a change list. Each methodology entry here says whether published profiles were reprocessed.](https://trooth.co/methodology#governance)
- [A company's evidenceWhat was read about one company and when, on its Trust Profile. The fuller record is in that company's workspace and is visible only to its members.](https://trooth.co/network)

Live availability is on the [status page](https://trooth.co/status), and every incident is recorded in the [incident ledger](https://trooth.co/incidents).

## Follow what changes

Email sends every entry. A feed can be narrowed to one area, or to the changes that need you to act.

- [Everything](https://trooth.co/changelog/rss.xml)
- [Needs action](https://trooth.co/changelog/rss.xml?action=required)
- [Security only](https://trooth.co/changelog/rss.xml?type=security)
- [Deprecations only](https://trooth.co/changelog/rss.xml?type=deprecation)
- [API](https://trooth.co/changelog/rss.xml?area=api)
- [MCP server](https://trooth.co/changelog/rss.xml?area=mcp)
- [Webhooks](https://trooth.co/changelog/rss.xml?area=webhooks)
- [CLI](https://trooth.co/changelog/rss.xml?area=cli)
- [Trust Profiles](https://trooth.co/changelog/rss.xml?area=trust-profile)
- [Methodology](https://trooth.co/changelog/rss.xml?area=methodology)
- [Badge](https://trooth.co/changelog/rss.xml?area=badge)

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current, evidence-backed Machine-Readable Trust Profile per company, rechecked on a schedule and signed so it can be replayed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    }
  ]
}
```
