Skip to main content
Skip to main content
Trust Center

Trooth

Trooth is the trust network for AI and software companies: a company connects its systems, Trooth witnesses what is true of them on a schedule, and buyers read the record with its sources and timestamps. This page is Trooth's own record, held to the same standard Trooth asks of every company on the Network. Trooth, LLC is a Florida limited liability company (L25000561494) based in Miami.

Resources

Compliance

Trust and Security Program Summary

Trooth's security, governance, privacy and compliance program at a glance, written for a buyer's first read.

GDPR Compliance Statement

How Trooth meets its obligations as a processor and a controller under the General Data Protection Regulation, article by article.

CCPA / CPRA Compliance Statement

Trooth's position under the California Consumer Privacy Act as amended, including the statement that personal information is not sold.

NIST Cybersecurity Framework 2.0 Profile

Trooth's current profile against the six CSF functions, with the outcomes it meets and the ones it does not yet.

NIST SP 800-171 Self-Assessment

A self-assessment against the 110 requirements, with the score, the method and the requirements marked not applicable.

Security, Privacy and Compliance Self-Assessment (CAIQ and SIG)

Trooth's completed self-assessment in the two questionnaire formats buyers most often send.

CISA Secure by Design Pledge

Trooth's signed pledge statement. CISA publishes the signatory roster; the roster entry is confirmed separately from this document.

Information Security Risk Register

Tracked risks with owners, likelihood, impact, treatment and review dates.

Information Asset Inventory

Catalogued systems and data assets by classification.

Policies

POL-01 Information Security Policy

The parent policy: principles, roles, the policy set and how it is kept current.

POL-02 Access Control Policy

Who is granted access to what, on what basis, and how it is removed.

POL-03 Password and Authentication Policy

Password strength, storage, multi-factor authentication, lockout and session rules.

POL-04 Data Classification and Handling Policy

The four classification levels and the handling each one requires.

POL-05 Encryption and Key Management Policy

Cryptography in transit and at rest, permitted algorithms, keys and secrets.

POL-06 Secure Development and Change Management Policy

One path to production: the gates every change passes, review, rollback and emergency change.

POL-07 Vulnerability Management Policy

How vulnerabilities are found, scored and fixed, with the remediation timelines.

POL-08 Logging, Monitoring and Access Review Policy

What is logged, how records are protected, alerting, and the access-review schedule.

POL-09 Incident Response Policy

Severities, response times, containment, customer notice and the post-mortem.

POL-10 Business Continuity and Disaster Recovery Policy

Recovery objectives, failure scenarios and what happens if the founder is unavailable.

POL-11 Backup and Data Retention Policy

Nightly encrypted backups, the restore rehearsal, and the retention schedule with disposal events.

POL-12 Asset Management Policy

How systems, data, code, domains, credentials and devices are inventoried and retired.

POL-13 Risk Management Policy

How risks are identified, scored, treated and reviewed, and where the register lives.

POL-14 Vendor and Third-Party Risk Management Policy

Due diligence before a vendor is engaged, the DPA requirement, review and exit.

POL-15 Acceptable Use Policy (Personnel)

What every person with access may and may not do with Company systems and data.

POL-16 Human Resources Security Policy

Screening, agreements, training and offboarding for anyone who acts for the Company.

POL-17 Physical and Environmental Security Policy

Physical controls inherited from the providers, and the rules for devices the Company holds.

POL-18 Data Residency and Regional Processing Policy

Where data rests, where it is processed, and how customers are told before either changes.

POL-19 AI Governance and Acceptable AI Use Policy

Where AI is used in the product and the business, the decisions a person always makes, and the rules for AI tools.

Security

Security Overview

How Trooth protects customer data: authentication, sessions, keys, tenant isolation, the audit ledger, encryption and monitoring.

Shared Responsibility Model

Who secures what, between Trooth, its infrastructure providers and the customer.

Access Monitoring and Logging Statement

What is recorded about access and use, where it is held, how it is protected and who reads it.

Automated Backup and Data Retention Statement

Nightly encrypted backups, the monthly restore proof, recovery objectives and the retention schedule.

Encryption in Transit and at Rest Assurance Statement

TLS, HSTS and AES-256 in transit and at rest, the permitted algorithms, and the checks anyone can run.

Network Architecture and Data Flow Disclosure

The components, the path of a request, every data flow, the trust boundaries and the residency region.

Vulnerability Disclosure Policy

How to report a vulnerability, what is in scope, and the safe harbor for good-faith research.

security.txt

The machine-readable contact and policy pointers at the standard well-known location.

Business Continuity Statement

Recovery objectives, backup cadence, the failure scenarios and the recovery path for each.

Incident Response Runbook

The operational runbook behind the published Incident Response Policy: who does what, in what order, with which accounts.

Business Continuity and Disaster Recovery Plan

The full plan behind the published statement, including the founder-unavailability runbook.

AI Governance

AI System Fact Sheet (Model Card)

What Trooth's AI-assisted features do, for whom, with what inputs and outputs, and their limitations.

AI Use Policy

Where generative AI is and is not used in the product, which decisions a person always makes, and the commitment not to train on customer content.

AI Disclosure

The automated systems that observe, organise and protect the Network, and what each one does and does not do.

EU AI Act Transparency and Risk Classification

Trooth's role, the risk category of each AI-assisted feature, and how each transparency obligation is met.

EU AI Act Compliance Statement

Trooth's position under the Regulation as a provider of limited-risk AI features.

EU AI Pact Commitments

The commitments Trooth signed with the European Commission ahead of the AI Act's application.

NIST AI RMF Conformance Statement

Trooth's AI governance activities mapped to the four functions of the framework, with the gaps named.

Regulatory

REG-01 Data Protection Impact Assessment

The risk assessment for the Network's processing: nine risks, the measures against each, the residual, and the three measures not yet in place.

REG-02 United States State Privacy Laws Statement

Trooth's position under the comprehensive privacy laws of the states other than California, and the universal answers every one of them asks for.

REG-03 Fair Credit Reporting Act Non-Applicability Statement

Why Trooth is not a consumer reporting agency and the Network is not a consumer report, element by element, and the limits that keep it true.

REG-04 PIPEDA Compliance Statement (Canada)

The ten fair information principles of Canada's PIPEDA, and a plain statement that Canadian data is stored in the United States.

REG-05 India Digital Personal Data Protection Act Statement

Trooth's position under India's Digital Personal Data Protection Act, 2023, obligation by obligation.

REG-06 Written Information Security Program (FTC Safeguards Rule)

A written information security program in the form the FTC Safeguards Rule prescribes, adopted voluntarily; the Rule does not reach Trooth.

REG-07 23 NYCRR Part 500 Third-Party Service Provider Statement

Section 500.11 answered point by point, for a NYDFS Covered Entity doing its third-party due diligence.

REG-08 NIS 2 Directive Supplier Statement

The Article 21(2) measures answered as a supplier, for an entity in scope of NIS 2. Trooth is not in scope itself.

REG-09 HIPAA Non-Applicability and Business Associate Readiness

Why HIPAA does not reach Trooth, where it would already stand against the Security Rule, and on what terms it would sign a BAA.

REG-10 EU AI Act Article 53 Non-Applicability and Model Transparency

Why the Article 53 obligations of a general-purpose AI model provider fall on the model providers and not on Trooth, and what Trooth can tell a buyer about the models it calls.

REG-11 DORA ICT Third-Party Service Provider Statement

What a financial entity needs for its DORA register of information, and the Article 30 provisions answered one by one.

REG-12 APRA CPS 230 Service Provider Statement (Australia)

Materiality under CPS 230, the paragraph 53 provisions answered, and the CPS 234 gaps a regulated entity should weigh.

Privacy

Privacy Policy

What is collected, why, for how long, who processes it, and how to exercise your rights.

Data Processing Addendum (DPA)

Processor terms with the standard contractual clauses, incorporated into customer terms without negotiation.

Sub-processor List

Every third party that processes customer personal data, with its purpose and processing region, and the change log.

Data Retention Summary

The maximum retention period and the disposal event for each kind of data.

Data Subject Rights Request Procedure

How to exercise access, correction, portability and erasure rights, and what happens within the 30 days.

Cookie Policy

Each cookie the site sets, what it is for and how long it lives.

Records of Processing Activities (RoPA)

GDPR Article 30 records: purposes, categories, recipients and retention.

Data Protection Impact Assessment (DPIA)

Risk assessment for the processing the Network performs on company and buyer data.

Data Retention and Disposal Schedule

The internal schedule behind the published summary, with disposal methods per system.