Resources
Compliance
Trust and Security Program Summary
Trooth's security, governance, privacy and compliance program at a glance, written for a buyer's first read.
GDPR Compliance Statement
How Trooth meets its obligations as a processor and a controller under the General Data Protection Regulation, article by article.
CCPA / CPRA Compliance Statement
Trooth's position under the California Consumer Privacy Act as amended, including the statement that personal information is not sold.
NIST Cybersecurity Framework 2.0 Profile
Trooth's current profile against the six CSF functions, with the outcomes it meets and the ones it does not yet.
NIST SP 800-171 Self-Assessment
A self-assessment against the 110 requirements, with the score, the method and the requirements marked not applicable.
Security, Privacy and Compliance Self-Assessment (CAIQ and SIG)
Trooth's completed self-assessment in the two questionnaire formats buyers most often send.
CISA Secure by Design Pledge
Trooth's signed pledge statement. CISA publishes the signatory roster; the roster entry is confirmed separately from this document.
Information Security Risk Register
Tracked risks with owners, likelihood, impact, treatment and review dates.
Information Asset Inventory
Catalogued systems and data assets by classification.
Policies
POL-01 Information Security Policy
The parent policy: principles, roles, the policy set and how it is kept current.
POL-02 Access Control Policy
Who is granted access to what, on what basis, and how it is removed.
POL-03 Password and Authentication Policy
Password strength, storage, multi-factor authentication, lockout and session rules.
POL-04 Data Classification and Handling Policy
The four classification levels and the handling each one requires.
POL-05 Encryption and Key Management Policy
Cryptography in transit and at rest, permitted algorithms, keys and secrets.
POL-06 Secure Development and Change Management Policy
One path to production: the gates every change passes, review, rollback and emergency change.
POL-07 Vulnerability Management Policy
How vulnerabilities are found, scored and fixed, with the remediation timelines.
POL-08 Logging, Monitoring and Access Review Policy
What is logged, how records are protected, alerting, and the access-review schedule.
POL-09 Incident Response Policy
Severities, response times, containment, customer notice and the post-mortem.
POL-10 Business Continuity and Disaster Recovery Policy
Recovery objectives, failure scenarios and what happens if the founder is unavailable.
POL-11 Backup and Data Retention Policy
Nightly encrypted backups, the restore rehearsal, and the retention schedule with disposal events.
POL-12 Asset Management Policy
How systems, data, code, domains, credentials and devices are inventoried and retired.
POL-13 Risk Management Policy
How risks are identified, scored, treated and reviewed, and where the register lives.
POL-14 Vendor and Third-Party Risk Management Policy
Due diligence before a vendor is engaged, the DPA requirement, review and exit.
POL-15 Acceptable Use Policy (Personnel)
What every person with access may and may not do with Company systems and data.
POL-16 Human Resources Security Policy
Screening, agreements, training and offboarding for anyone who acts for the Company.
POL-17 Physical and Environmental Security Policy
Physical controls inherited from the providers, and the rules for devices the Company holds.
POL-18 Data Residency and Regional Processing Policy
Where data rests, where it is processed, and how customers are told before either changes.
POL-19 AI Governance and Acceptable AI Use Policy
Where AI is used in the product and the business, the decisions a person always makes, and the rules for AI tools.
Security
Security Overview
How Trooth protects customer data: authentication, sessions, keys, tenant isolation, the audit ledger, encryption and monitoring.
Access Monitoring and Logging Statement
What is recorded about access and use, where it is held, how it is protected and who reads it.
Automated Backup and Data Retention Statement
Nightly encrypted backups, the monthly restore proof, recovery objectives and the retention schedule.
Encryption in Transit and at Rest Assurance Statement
TLS, HSTS and AES-256 in transit and at rest, the permitted algorithms, and the checks anyone can run.
Network Architecture and Data Flow Disclosure
The components, the path of a request, every data flow, the trust boundaries and the residency region.
Vulnerability Disclosure Policy
How to report a vulnerability, what is in scope, and the safe harbor for good-faith research.
security.txt
The machine-readable contact and policy pointers at the standard well-known location.
Business Continuity Statement
Recovery objectives, backup cadence, the failure scenarios and the recovery path for each.
Incident Response Runbook
The operational runbook behind the published Incident Response Policy: who does what, in what order, with which accounts.
Business Continuity and Disaster Recovery Plan
The full plan behind the published statement, including the founder-unavailability runbook.
AI Governance
AI System Fact Sheet (Model Card)
What Trooth's AI-assisted features do, for whom, with what inputs and outputs, and their limitations.
AI Use Policy
Where generative AI is and is not used in the product, which decisions a person always makes, and the commitment not to train on customer content.
AI Disclosure
The automated systems that observe, organise and protect the Network, and what each one does and does not do.
EU AI Act Transparency and Risk Classification
Trooth's role, the risk category of each AI-assisted feature, and how each transparency obligation is met.
EU AI Act Compliance Statement
Trooth's position under the Regulation as a provider of limited-risk AI features.
EU AI Pact Commitments
The commitments Trooth signed with the European Commission ahead of the AI Act's application.
NIST AI RMF Conformance Statement
Trooth's AI governance activities mapped to the four functions of the framework, with the gaps named.
Regulatory
REG-01 Data Protection Impact Assessment
The risk assessment for the Network's processing: nine risks, the measures against each, the residual, and the three measures not yet in place.
REG-02 United States State Privacy Laws Statement
Trooth's position under the comprehensive privacy laws of the states other than California, and the universal answers every one of them asks for.
REG-03 Fair Credit Reporting Act Non-Applicability Statement
Why Trooth is not a consumer reporting agency and the Network is not a consumer report, element by element, and the limits that keep it true.
REG-04 PIPEDA Compliance Statement (Canada)
The ten fair information principles of Canada's PIPEDA, and a plain statement that Canadian data is stored in the United States.
REG-05 India Digital Personal Data Protection Act Statement
Trooth's position under India's Digital Personal Data Protection Act, 2023, obligation by obligation.
REG-06 Written Information Security Program (FTC Safeguards Rule)
A written information security program in the form the FTC Safeguards Rule prescribes, adopted voluntarily; the Rule does not reach Trooth.
REG-07 23 NYCRR Part 500 Third-Party Service Provider Statement
Section 500.11 answered point by point, for a NYDFS Covered Entity doing its third-party due diligence.
REG-08 NIS 2 Directive Supplier Statement
The Article 21(2) measures answered as a supplier, for an entity in scope of NIS 2. Trooth is not in scope itself.
REG-09 HIPAA Non-Applicability and Business Associate Readiness
Why HIPAA does not reach Trooth, where it would already stand against the Security Rule, and on what terms it would sign a BAA.
REG-10 EU AI Act Article 53 Non-Applicability and Model Transparency
Why the Article 53 obligations of a general-purpose AI model provider fall on the model providers and not on Trooth, and what Trooth can tell a buyer about the models it calls.
REG-11 DORA ICT Third-Party Service Provider Statement
What a financial entity needs for its DORA register of information, and the Article 30 provisions answered one by one.
REG-12 APRA CPS 230 Service Provider Statement (Australia)
Materiality under CPS 230, the paragraph 53 provisions answered, and the CPS 234 gaps a regulated entity should weigh.
Privacy
Privacy Policy
What is collected, why, for how long, who processes it, and how to exercise your rights.
Data Processing Addendum (DPA)
Processor terms with the standard contractual clauses, incorporated into customer terms without negotiation.
Sub-processor List
Every third party that processes customer personal data, with its purpose and processing region, and the change log.
Data Retention Summary
The maximum retention period and the disposal event for each kind of data.
Data Subject Rights Request Procedure
How to exercise access, correction, portability and erasure rights, and what happens within the 30 days.
Records of Processing Activities (RoPA)
GDPR Article 30 records: purposes, categories, recipients and retention.
Data Protection Impact Assessment (DPIA)
Risk assessment for the processing the Network performs on company and buyer data.
Data Retention and Disposal Schedule
The internal schedule behind the published summary, with disposal methods per system.
Legal
Terms of Service
The terms every account accepts.
Acceptable Use Policy
What may and may not be done with the product.
End User License Agreement
License terms for the software.
Service Level Agreement
Availability commitments and the remedy when they are not met.
API Terms
Terms for programmatic access, keys and rate limits.
Accessibility Statement
Trooth's conformance target, what is tested in the build, and how to report a barrier.