Skip to main content

How Trooth trust works.

Anyone can say they take security seriously. Here is how you tell the difference. Who a company is gets confirmed once. What is true about it gets checked again and again, with a source and a date on every fact, and a receipt you can check yourself.

Three kinds of evidence. Each one checkable.

Trust isn't a single stamp. Identity is confirmed once and stands. Facts are checked with dates and rechecked on a schedule. A third party can attest on top of both. Every fact says which kind it is, so you can see what a company has shown and what it has not.

  1. 1
    Layer 1

    Confirmed identity

    Who they are, checked once: a named human confirmed, domain control shown, and every statement cryptographically signed by that identity. Anything the company says beyond that is labeled Stated, never dressed up as checked.

    add the next layer by connecting your live systems
  2. 2
    Layer 2

    Witnessed facts

    What is true right now, checked against the vendor's live systems, Okta, AWS, GitHub, and mapped to SOC 2 and ISO 27001 controls. Each fact carries its source and an as-of date, re-checked on its own cadence, tamper-evident and independently checkable.

    add the next layer with an independent CPA's SOC 2 opinion
  3. 3
    Layer 3third-party attested

    Confirmed: SOC 2, kept current

    A named counterparty attested: an independent CPA's SOC 2 opinion, kept live by continuous witnessing, so the report reflects today, not the day it was signed.

Why you can trust this without trusting us.

Their evidence, not our opinion

Every claim points back to the vendor's own systems and records. We don't ask you to take our word, we show you theirs.

Standards you already know

Claims are mapped to SOC 2, ISO 27001, GDPR, and the EU AI Act, the same frameworks your security and legal teams already use.

Cryptographically auditable

Each profile carries a cryptographic signature. You can check the proof yourself, independently, without contacting us.

Trooth is the messenger, not the authority.

We issue and sign the proof. We don't replace your auditor, and we don't replace your judgment.

01

We issue and sign the proof

Trooth witnesses each claim and applies a cryptographic outer signature. We attest that we saw the evidence, we do not author the vendor's claim.

02

Independent auditors can ingest it

Trooth-issued proofs follow an open, documented format. Auditors, buyers and your own tooling can read and verify them without a Trooth login.

03

We run our own company on Trooth

Trooth's own page is published the same way: identity confirmed, facts witnessed with dates. We hold ourselves to the protocol we ask of every vendor.

Check a company yourself.

Check any company, free. Every page reads live state, not a static PDF, and every claim carries the date it was last checked.

Browse the Trooth Network