---
title: "Trust Center - Trooth"
description: "Trooth, LLC's own Trust Center: the controls it attests to with the evidence for each, the ones it does not have yet, its public statements and policies, its sub-processors, and how to request documents under NDA."
canonical_url: "https://trooth.co/security"
markdown_url: "https://trooth.co/security.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

## Compliance

### Published

- [EU AI PactSignatory, listed by the European Commission](https://digital-strategy.ec.europa.eu/en/policies/ai-pact)
- [CISA Secure by DesignPledge signed and published; CISA listing not yet confirmed](https://trooth.co/security/cisa-secure-by-design-pledge.pdf)
- [GDPRStatement published](https://trooth.co/security/gdpr-compliance-statement.pdf)
- [CCPA / CPRAStatement published](https://trooth.co/security/ccpa-compliance-statement.pdf)
- [EU AI ActStatement published](https://trooth.co/security/eu-ai-act-compliance-statement.pdf)
- [NIST CSF 2.0Alignment, self-attested](https://trooth.co/security/nist-csf-profile.pdf)
- [NIST AI RMFAlignment, self-attested](https://trooth.co/security/nist-ai-rmf-conformance.pdf)
- [NIST SP 800-171Alignment, self-attested](https://trooth.co/security/nist-800-171-self-assessment.pdf)

### Aligned, on our roadmap

- SOC 2 Type IIAligned framework, on our roadmap. Not examined; no report exists.
- ISO/IEC 27001:2022Aligned framework, on our roadmap. Not certified.
- ISO/IEC 42001:2023Aligned framework, on our roadmap. Not certified.
- ISO/IEC 27701Aligned framework, on our roadmap. Not certified.
- [CSA STAR Level 1Self-assessment prepared; submission to the registry on our roadmap](https://trooth.co/trust/Trooth-CAIQ-SIG-Self-Assessment.pdf)

### Not applicable

- PCI DSS 4.0Trooth takes no payment and stores no card data
- [HIPAATrooth processes no protected health information](https://trooth.co/trust/regulatory/REG-09-hipaa-non-applicability-and-baa-readiness.pdf)

## Resources

[View all](https://trooth.co/security/resources)

### Compliance

- [View 5 more](https://trooth.co/security/resources#compliance)

### Policies

- [View 15 more](https://trooth.co/security/resources#policies)

### Security

- [View 7 more](https://trooth.co/security/resources#security)

### AI Governance

- [AI Use Policy](https://trooth.co/ai-policy)
- [AI Disclosure](https://trooth.co/ai-disclosure)
- [View 3 more](https://trooth.co/security/resources#ai)

### Regulatory

- [View 8 more](https://trooth.co/security/resources#regulatory)

### Privacy

- [Privacy Policy](https://trooth.co/privacy)
- [Data Processing Addendum (DPA)](https://trooth.co/dpa)
- [Sub-processor List](https://trooth.co/subprocessors)
- [Data Retention Summary](https://trooth.co/retention)
- [View 5 more](https://trooth.co/security/resources#privacy)

### Legal

- [Terms of Service](https://trooth.co/terms)
- [Acceptable Use Policy](https://trooth.co/aup)
- [End User License Agreement](https://trooth.co/eula)
- [Service Level Agreement](https://trooth.co/sla)
- [View 2 more](https://trooth.co/security/resources#legal)

## Controls

Updated September 23, 2026

[View all](https://trooth.co/security/controls)

[Infrastructure Security](https://trooth.co/security/controls#infrastructure-security)

- AttestedEncryption in transit enforced
- AttestedEncryption at rest
- AttestedTenant data is separated by row-level security in the database

[View 7 more Infrastructure Security controls](https://trooth.co/security/controls#infrastructure-security)

[Organizational Security](https://trooth.co/security/controls#organizational-security)

- AttestedSecurity policies established and reviewed
- AttestedSecurity roles and responsibilities defined
- AttestedInventory of systems and data assets maintained

[View 6 more Organizational Security controls](https://trooth.co/security/controls#organizational-security)

[Internal Security Procedures](https://trooth.co/security/controls#internal-security-procedures)

- AttestedIncident response plan established
- AttestedBreach notification within 72 hours
- AttestedBusiness continuity and disaster recovery plan established

[View 6 more Internal Security Procedures controls](https://trooth.co/security/controls#internal-security-procedures)

[AI Security & Compliance](https://trooth.co/security/controls#ai-security-and-compliance)

- AttestedAI systems are inventoried and described in a published fact sheet
- AttestedAI use policy published
- AttestedCustomer data is not used to train models

[View 7 more AI Security & Compliance controls](https://trooth.co/security/controls#ai-security-and-compliance)

[Product Security](https://trooth.co/security/controls#product-security)

- AttestedMulti-factor authentication available to every account
- AttestedPasswords stored as salted hashes with rising work factors
- AttestedSessions in httpOnly, secure cookies with a fixed expiry

[View 10 more Product Security controls](https://trooth.co/security/controls#product-security)

[Data and Privacy](https://trooth.co/security/controls#data-and-privacy)

- AttestedPrivacy policy published and maintained
- AttestedData processing addendum available
- AttestedSub-processor list published with 30 days' notice of change

[View 9 more Data and Privacy controls](https://trooth.co/security/controls#data-and-privacy)

## Data collected

- Collected:Customer personally identifiable information
- Collected:Configuration signals from systems a customer connects
- Not collected:Credit card information
- Not collected:Personal health information

## Sub-processors

[View all](https://trooth.co/security/subprocessors)

Cloudflare, Inc. Edge compute and network security services, form bot checks (Turnstile), and AI inference (Workers AI) for the Kyrie assistant and questionnaire draftingGlobal edge

Core product

WorkOS, Inc. Authentication, single sign-on (SSO), and OAuthUnited States

Core product

Amazon Web Services, Inc. Cloud storage and key managementUnited States and European Union

Core product

Anthropic, PBC Internal-use generative AI for productivityUnited States

Internal tools

## FAQ

[View all](https://trooth.co/security/faq)

## Updates

[View all](https://trooth.co/security/updates)

### The change-control description is corrected to what the deploy workflow enforces

Security

Published September 23, 2026

The control for production deploys said that direct deploys from a laptop were refused by the workflow's own checks. The workflow has no such check, so the sentence was withdrawn. The control now says what holds: the routine path is the GitHub Actions workflow, which does not upload until every build gate succeeds; the gates are also part of the build command, so a build made with the project's configuration runs them; and nothing refuses a deploy made outside GitHub by someone holding the hosting account's deploy token, so access to production rests on who holds that token.

### The compliance statements are rewritten, twelve regulatory statements are published, and the compliance list says what each record is

Compliance

Published September 18, 2026

The eight compliance statements of June were rewritten rather than patched. The earlier set described products Trooth does not have, a mobile application it never shipped and a time-stamping scheme it never built, so correcting the names would have left claims with nothing behind them. Each is re-issued as version 2.0, effective today, without a signature, and describes the company that exists: one product, twelve sub-processors, no payment, no health data.

### The policy set is published: nineteen policies and four assurance statements, no signature required

Compliance

Published September 18, 2026

The information security policy set that was available under NDA is now public on the Resources tab, as nineteen numbered policies (POL-01 to POL-19) that take effect as published statements of the company rather than as signed documents. The signed set of May 25, 2026 is superseded. Four assurance statements join them: access monitoring and logging, automated backup and data retention, encryption in transit and at rest, and a network architecture and data flow disclosure.

### The Trust Center is reorganized around controls, resources and evidence

General

Published September 18, 2026

This page now lists the controls Trooth states it has in place, in six categories, each with the evidence behind it, and names the controls Trooth does not have yet rather than leaving them out. Resources are grouped by topic with their access level shown; the sub-processor tab reads from the published sub-processor list so the two cannot differ; and the page gains subscriptions, a question form and an access request that a person answers within two business days.

## Request documents under NDA

The risk register, the asset inventory, the records of processing, the impact assessment, the incident response runbook, the continuity plan and the internal retention schedule are shared with customers and qualified prospects under a mutual non-disclosure agreement. A person reviews every request and replies within two business days with the documents and the NDA for signature.

[Request access](https://trooth.co/security?requestAccessOpen=true)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current, evidence-backed Machine-Readable Trust Profile per company, rechecked on a schedule and signed so it can be replayed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```
