Business Continuity and Incident Communications
1. Purpose and honest scope
This document describes how Trooth is built to stay available, how incidents are detected, and how Trooth communicates when something goes wrong. Trooth is a small company that builds on managed infrastructure; the resilience described here is a combination of vendor capabilities and Trooth's own procedures, and this document does not claim more than that.
2. How the Service is built to stay up
The web application is served from a managed multi-region edge platform. The database is a managed PostgreSQL service with automated backups and vendor-provided point-in-time restore capability. Authentication is delegated to a managed identity provider. Each of these vendors, and what it does, is on the Sub-processor List. In addition to vendor backups, Trooth maintains an offline vault procedure for its own copies of critical data.
3. How problems are detected
The Service exposes a health endpoint that checks its own dependencies, external monitors probe availability from outside Trooth's infrastructure, and application errors are reported to an error-tracking service. A production deployment that fails its required checks reports itself unhealthy rather than pretending otherwise.
4. How Trooth communicates during an incident
For availability incidents, Trooth communicates with affected customers by email as the situation warrants. For security incidents involving personal data, notification obligations and timelines are governed by the Data Processing Addendum for customers with a DPA, and by applicable law for everyone; this document does not restate those timelines, so the two can never disagree. Security reports from outside Trooth are received under the Vulnerability Disclosure Policy at security@trooth.co.
5. Dependencies and their limits
Trooth depends on the vendors on the Sub-processor List, and an outage at one of them can impair the Service. Where that happens, Trooth's responsibility is what the Terms of Service say, including the force majeure provision. Choosing well-operated managed vendors is itself part of the continuity posture: each vendor named runs its own redundancy and its own security program, which Trooth evaluates when it adopts one.
6. Data return
If your relationship with Trooth ends, export and return of your data are governed by the Terms of Service and, where one is in place, the Data Processing Addendum.
7. Review
This document is reviewed as the Service evolves, and its effective date changes when its substance does.
8. Contact
Availability questions: support@trooth.co. Security incidents: security@trooth.co.