---
title: "A bill of materials for every Worker, and Trooth's own record corrected: Trooth changelog - Trooth"
description: "Every Cloudflare Worker behind api.trooth.co now has a public software bill of materials, and two claims on Trooth's own Trust Profile were corrected to match its policies."
canonical_url: "https://trooth.co/changelog/2026-09-26-worker-bills-of-materials"
markdown_url: "https://trooth.co/changelog/2026-09-26-worker-bills-of-materials.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

New

September 26, 20261 minute read

# A bill of materials for every Worker, and Trooth's own record corrected

Every Cloudflare Worker behind api.trooth.co now has a public software bill of materials, and two claims on Trooth's own Trust Profile were corrected to match its policies.

## What changed

Each of the eight Cloudflare Workers behind api.trooth.co now has a public software bill of materials, one CycloneDX file per Worker listing every package its lockfile resolves, with the repository commit it was read at. Until today only the web application had one. Trooth's own Trust Profile also said two things its policies did not: a list price of By quote, while Trooth is free, and a one-hour recovery point objective, while the continuity policy states 24 hours. Both now match the policy.

## Why it changed

Only the web application had a bill of materials, and Trooth's own record contradicted its policies on price and on recovery point.

## Who is affected

- **Affected:** Security reviewers checking what Trooth runs, and anyone who read Trooth's own Trust Profile before the correction.
- **Availability:** Public. No account needed.
- **Release stage:** Available.
- **Areas:** Platform, Trust Profiles.

## What to do

**No action required.** The bills are new files and the corrected values are Trooth's own. Nothing that existed changed shape.

## Dates

- **Announced:** September 26, 2026, the day this entry was written. Entries are never backdated.
- **Released:** September 26, 2026.
- **Trooth's record corrected and read back:** September 26, 2026.

## What this does not fix

A Worker's bill is read from its lockfile, not from the script Cloudflare serves. The web application's bill lists direct dependencies; its lockfile holds the rest.

## Corrections and later changes

- **Corrected September 26, 2026:** Trooth's Trust Profile listed a price of By quote and a one-hour recovery point objective. Both now match policy: Trooth is free, and the recovery point objective is 24 hours.

## Read more

- [Worker bills of materials](https://trooth.co/sbom/workers/index.json)
- [Web application bill of materials](https://trooth.co/sbom.json)
- [Trooth's Trust Profile](https://trooth.co/network/company/trooth)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Dates
- What this does not fix
- Corrections and later changes
- Read more

[New](https://trooth.co/changelog?type=new)[Fix](https://trooth.co/changelog?type=fix)[Platform](https://trooth.co/changelog?area=platform)[Trust Profiles](https://trooth.co/changelog?area=trust-profile)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [SEP.27NewA public feedback board, and a comparison you can start with any two companiesNetwork +1](https://trooth.co/changelog/2026-09-27-feedback-board-and-comparison)
- [SEP.27ImprovementA developer reference you can build from, and a changelog you can followAPI +1](https://trooth.co/changelog/2026-09-27-developer-reference-and-changelog)
- [SEP.27MethodologyThe methodology is versioned, with an example profile you can inspectMethodology +1](https://trooth.co/changelog/2026-09-27-methodology-versioned)
- [SEP.26ImprovementCounts on a profile now come from the signed witness statementTrust Profiles +2](https://trooth.co/changelog/2026-09-26-counts-from-signed-statement)
- [SEP.26ImprovementDisputes are handled privately; framework rollups and the old badge are retiredTrust Profiles +4](https://trooth.co/changelog/2026-09-26-disputes-private-rollups-retired)
- [SEP.04DeprecationThe 0-100 figure is deletedTrust Profiles +3](https://trooth.co/changelog/2026-09-04-single-figure-deleted)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[Platform only](https://trooth.co/changelog/rss.xml?area=platform)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current, evidence-backed Machine-Readable Trust Profile per company, rechecked on a schedule and signed so it can be replayed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "A bill of materials for every Worker, and Trooth's own record corrected",
      "item": "https://trooth.co/changelog/2026-09-26-worker-bills-of-materials"
    }
  ]
}
```
