Skip to main content
Skip to main content
Trust Center

Trooth

Trooth is the trust network for AI and software companies: a company connects its systems, Trooth witnesses what is true of them on a schedule, and buyers read the record with its sources and timestamps. This page is Trooth's own record, held to the same standard Trooth asks of every company on the Network. Trooth, LLC is a Florida limited liability company (L25000561494) based in Miami.

Updates

The compliance statements are rewritten, twelve regulatory statements are published, and the compliance list says what each standing is

Compliance

Published September 18, 2026

The eight compliance statements of June were rewritten rather than patched. The earlier set described products Trooth does not have, a mobile application it never shipped and a time-stamping scheme it never built, so correcting the names would have left claims with nothing behind them. Each is re-issued as version 2.0, effective today, without a signature, and describes the company that exists: one product, twelve sub-processors, no payment, no health data.

The policy set is published: nineteen policies and four assurance statements, no signature required

Compliance

Published September 18, 2026

The information security policy set that was available under NDA is now public on the Resources tab, as nineteen numbered policies (POL-01 to POL-19) that take effect as published statements of the company rather than as signed documents. The signed set of 2026-05-25 is superseded. Four assurance statements join them: access monitoring and logging, automated backup and data retention, encryption in transit and at rest, and a network architecture and data flow disclosure.

The Trust Center is reorganised around controls, resources and evidence

General

Published September 18, 2026

This page now lists the controls Trooth attests to in six categories, each with the evidence behind it, and names the controls Trooth does not have yet rather than leaving them out. Resources are grouped by topic with their access level shown; the sub-processor tab reads from the published sub-processor list so the two cannot differ; and the page gains subscriptions, a question form and an access request that a person answers within two business days.

Tenant isolation proven against a live deployment with real sessions

Security

Published September 17, 2026

A harness that signs in as three real accounts in three workspaces and sends each one foreign and forged identifiers into every covered surface ran green against a production-configured deployment. Its earlier runs found three things, each fixed the same day: a refusal returned in the wrong order, a refusal reported as an outage in a notification email, and a forged identifier answered with a server error instead of a not-found. The harness now insists on the right answer in each case.

EU AI Pact listing confirmed on the Commission's roster

Compliance

Published September 17, 2026

The European Commission's public roster of AI Pact signatories lists Trooth. The listing is a fact a third party publishes in a register Trooth does not control, which is the standard this page holds itself to before it shows a registration.

First restore rehearsal completed

Security

Published September 10, 2026

A workflow restored a nightly encrypted backup into a fresh database and checked that the tables and row counts came back. It completed successfully and is scheduled to run monthly from now on.

Sub-processor list: Stripe and Expo removed

Subprocessors

Published September 4, 2026

Stripe was removed because Trooth takes no payment and processes no card data. Expo was removed because Trooth distributes no mobile application. Neither removal changes any processing of customer personal data.