Connector and Read-Only Access Disclosure
1. What a connector is
A connector links a system your company already runs to Trooth so that Trooth can witness signals from it: the configuration and status facts that become the evidence on your Network profile. Connectors exist because self-attested claims are not evidence. This document explains what access a connector has, what Trooth reads through it, and how to take that access away.
2. How authorization works
Connectors authorize through OAuth: you sign in to the connected provider yourself, on that provider's own pages, and approve a specific scope of access. Trooth never asks for and never sees your password to the connected system. The OAuth broker Trooth uses for this handshake appears on the Sub-processor List, with the note that it processes data only when a customer connects an integration.
3. Read access, by design
Connectors are designed for reading. Witnessing observes a connected system and records what it saw, with source and timestamp; it does not change settings, write data, or take action in the connected system. The scopes requested at consent are the ones the connector needs to observe, and the provider's consent screen shows you exactly what is being granted before you approve it.
4. What is collected
Through a connector, Trooth reads the signals the methodology describes: configuration state, security posture facts, and status information from the connected system. Observed signals become witnessed evidence with a source and a timestamp, re-read on a recurring schedule. What Trooth retains and for how long is governed by the Privacy Policy and the Data Retention Summary.
5. Revoking access
You can disconnect a connector from your workspace at any time, and you can also revoke Trooth's access directly at the connected provider; either is effective. After revocation, Trooth can no longer re-read the system: previously witnessed facts stop refreshing and age accordingly, which your profile reflects honestly. Evidence already recorded remains subject to the retention rules above.
6. Token security
OAuth tokens for connected systems are handled through the broker named on the Sub-processor List and are transmitted over TLS. Trooth's own access to production systems is role-restricted, as the Trust Center describes.
7. Contact
Questions about connector access: security@trooth.co or support@trooth.co.