Skip to main content
Improvement

2 minute read

Retention with an end, continuity powers made clear, and production watched

The records Trooth kept indefinitely now have an end, the continuity document says what the Continuity Contact may do in the first hours of an incident, every control not yet in place carries a date, and a production deploy made outside the deploy workflow is now detected within the hour.

What changed

Copies of cookie choices were kept for as long as they might be needed. They are now deleted 24 months after the choice, and the page and browser details in them are removed after 90 days; the rest is what shows the choice was made. A dispute's filer address, stated relationship and message are removed 24 months after the dispute is resolved, while the public correction history, which names no person, stays on the company's Trust Profile. The Retention Schedule's section 4 now gives each record kept longer than an account its purpose, basis, contents, readers and end, and the removals run every day. The continuity document now separates the first hours of an incident from succession: if the founder cannot be reached within 4 hours, the Continuity Contact may take the service offline, revoke a compromised credential or key, withdraw a harmful page and post a status notice, and nothing more, and a compromised signing key is marked compromised rather than deleted. Deletions the Retention Schedule requires are no longer contradicted by the instruction to preserve records. The arrangement has not yet been exercised, and the document says so. On the security page, each control not yet in place now carries its state and date, and the first access review was run and is recorded as partly complete. Trooth's own company record was corrected where it disagreed with its policies: every sign-in method, Transport Layer Security (TLS) 1.2 or later, the current privacy notice, where data is stored, processed, backed up and logged, and no private networking. Production deploys are now recorded by the deploy workflow where a hosting credential cannot write, and an hourly drift check reports anything serving trooth.co that the workflow did not record. The workflow's deploy token now expires after 90 days.

Why it changed

The audit of September 28, 2026 found two indefinite retention exceptions without an end, continuity powers that contradicted each other, planned controls without dates, and a deploy path that nothing watched.

Who is affected

  • Affected: Anyone who has used the cookie panel or filed a dispute, and anyone relying on Trooth's security page or continuity arrangements. Nothing a developer calls changed.
  • Availability: Public. No account needed.
  • Release stage: Available.
  • Areas: Legal, Platform, Trust Profiles.

What to do

No action required. Nothing to do.

Dates

  • Announced: September 28, 2026, the day this entry was written. Entries are never backdated.
  • Released: September 28, 2026.

What this does not fix

The hourly drift check detects a deploy made outside the workflow; it does not prevent one, because the hosting provider offers no way to for a single-owner team. The first access review still has providers to read, and the continuity arrangement is appointed but not yet exercised.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSLegal onlyNeeds action

View as agent