Trooth's log now asks independent witnesses to cosign each checkpoint, every entry has a receipt in the COSE format, and each public record reading is signed and entered in the log. The public record is shown on Trust Profiles.
What changed
The log sends each new checkpoint, with a proof that it extends the last one, to the staging witnesses of the witness network run by Geomys, Mullvad and TrustFabric, and serves their cosignatures on the checkpoint. trooth log checkpoint and trooth log monitor say which of them cosigned, and --witnesses requires a number of them. trooth log receipt checks an entry's receipt in the COSE format (RFC 9942) against the log key published at api.trooth.co/.well-known/scitt-keys. Each public record reading is now named by its fingerprint in a statement Trooth signs and enters in the log, and trooth public-record checks that statement, its key and its log entry. The reading adds the legal entity's identifier, the domain's certificates in public certificate logs, its security contact, the pages its home page links to, an exact-name check against the US Treasury sanctions list, and a fingerprint of every response it read, which Trooth keeps so a disputed fact can be replayed. A Trust Profile shows the reading when one was taken in the last day, and a reader can ask for one there.
Why it changed
A log checked only by its own operator and by monitors detects a rewritten history only later. Witnesses refuse to cosign one, so a reader who asks for cosignatures never accepts it. A public record that is not signed cannot be held to what it said.
Who is affected
- Affected: Anyone relying on a Trooth reading or a company's public record, and anyone watching that Trooth does not change its history.
- Availability: npm, as trooth 0.11.0; on Trust Profiles, in the Identity section. No account.
- Release stage: Available.
- Areas: CLI, API.
What to do
No action required. Nothing is required. Run trooth log checkpoint to see which witnesses cosigned, or open a company's Identity section to see its public record.
Versions and migration
- trooth:
0.11.0
Dates
- Announced: October 7, 2026, the day this entry was written. Entries are never backdated.
- Released: October 7, 2026.
What this does not fix
Cosignatures begin when the witness network accepts the log onto its staging list; the witnesses are staging services and the network has no production list yet. The log key is held in software and used by one person; hardware custody and a second approver are planned and described in docs/KEY-CEREMONY.md. A name match on the sanctions list is not an identification. Contractor registrations, patent and trademark records and state registers are not read.