---
title: "Retention with an end, continuity powers made clear, and production watched: Trooth changelog - Trooth"
description: "The records Trooth kept indefinitely now have an end, the continuity document says what the Continuity Contact may do in the first hours of an incident, every control not yet in place carries a date, and a production deploy made outside the deploy workflow is now detected within the hour."
canonical_url: "https://trooth.co/changelog/2026-09-28-retention-continuity-and-deploy-controls"
markdown_url: "https://trooth.co/changelog/2026-09-28-retention-continuity-and-deploy-controls.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

Improvement

September 28, 20262 minute read

# Retention with an end, continuity powers made clear, and production watched

The records Trooth kept indefinitely now have an end, the continuity document says what the Continuity Contact may do in the first hours of an incident, every control not yet in place carries a date, and a production deploy made outside the deploy workflow is now detected within the hour.

## What changed

Copies of cookie choices were kept for as long as they might be needed. They are now deleted 24 months after the choice, and the page and browser details in them are removed after 90 days; the rest is what shows the choice was made. A dispute's filer address, stated relationship and message are removed 24 months after the dispute is resolved, while the public correction history, which names no person, stays on the company's Trust Profile. The Retention Schedule's section 4 now gives each record kept longer than an account its purpose, basis, contents, readers and end, and the removals run every day. The continuity document now separates the first hours of an incident from succession: if the founder cannot be reached within 4 hours, the Continuity Contact may take the service offline, revoke a compromised credential or key, withdraw a harmful page and post a status notice, and nothing more, and a compromised signing key is marked compromised rather than deleted. Deletions the Retention Schedule requires are no longer contradicted by the instruction to preserve records. The arrangement has not yet been exercised, and the document says so. On the security page, each control not yet in place now carries its state and date, and the first access review was run and is recorded as partly complete. Trooth's own company record was corrected where it disagreed with its policies: every sign-in method, Transport Layer Security (TLS) 1.2 or later, the current privacy notice, where data is stored, processed, backed up and logged, and no private networking. Production deploys are now recorded by the deploy workflow where a hosting credential cannot write, and an hourly drift check reports anything serving trooth.co that the workflow did not record. The workflow's deploy token now expires after 90 days.

## Why it changed

The audit of September 28, 2026 found two indefinite retention exceptions without an end, continuity powers that contradicted each other, planned controls without dates, and a deploy path that nothing watched.

## Who is affected

- **Affected:** Anyone who has used the cookie panel or filed a dispute, and anyone relying on Trooth's security page or continuity arrangements. Nothing a developer calls changed.
- **Availability:** Public. No account needed.
- **Release stage:** Available.
- **Areas:** Legal, Platform, Trust Profiles.

## What to do

**No action required.** Nothing to do.

## Dates

- **Announced:** September 28, 2026, the day this entry was written. Entries are never backdated.
- **Released:** September 28, 2026.

## What this does not fix

The hourly drift check detects a deploy made outside the workflow; it does not prevent one, because the hosting provider offers no way to for a single-owner team. The first access review still has providers to read, and the continuity arrangement is appointed but not yet exercised.

## Read more

- [Retention Schedule](https://trooth.co/retention)
- [Business Continuity, Succession and Service Transition](https://trooth.co/continuity)
- [Security controls](https://trooth.co/security/controls)
- [Trooth's company record](https://trooth.co/network/company/trooth)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Dates
- What this does not fix
- Read more

[Improvement](https://trooth.co/changelog?type=improvement)[Fix](https://trooth.co/changelog?type=fix)[Security](https://trooth.co/changelog?type=security)[Legal](https://trooth.co/changelog?area=legal)[Platform](https://trooth.co/changelog?area=platform)[Trust Profiles](https://trooth.co/changelog?area=trust-profile)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [SEP.28FixCorrections from the September 28 audit: contract 1, one interface catalog, a complete bill of materialsAPI +5](https://trooth.co/changelog/2026-09-28-fresh-audit-corrections)
- [SEP.28FixA site-wide quality sweep: underlined legal links, keyboard-reachable code, readable small textPlatform +1](https://trooth.co/changelog/2026-09-28-site-wide-quality-sweep)
- [SEP.27ImprovementContinuity, succession and service transition, written downLegal](https://trooth.co/changelog/2026-09-27-continuity-succession-and-transition)
- [SEP.27MethodologyThe two Standards and the About page, rebuilt as referencesMethodology +1](https://trooth.co/changelog/2026-09-27-standards-and-about-page-as-references)
- [SEP.27NewA public feedback board, and a comparison you can start with any two companiesNetwork +1](https://trooth.co/changelog/2026-09-27-feedback-board-and-comparison)
- [SEP.27ImprovementA developer reference you can build from, and a changelog you can followAPI +1](https://trooth.co/changelog/2026-09-27-developer-reference-and-changelog)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[Legal only](https://trooth.co/changelog/rss.xml?area=legal)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current Machine-Readable Trust Profile per company, each fact labeled with its source. The part Trooth witnessed is a signed statement whose signature anyone can check later; the company's own declarations are not signed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Retention with an end, continuity powers made clear, and production watched",
      "item": "https://trooth.co/changelog/2026-09-28-retention-continuity-and-deploy-controls"
    }
  ]
}
```
