Skip to main content
Skip to main content
Trust Center

Trooth

Trooth is the trust network for AI and software companies: a company connects its systems, Trooth witnesses what is true of them on a schedule, and buyers read the record with its sources and timestamps. This page is Trooth's own record, held to the same standard Trooth asks of every company on the Network. Trooth, LLC is a Florida limited liability company (L25000561494) based in Miami.

Compliance

Aligned, on our roadmap

Not applicable

Resources

View all

Compliance

Policies

Security

AI Governance

Regulatory

Controls

Updated September 18, 2026
View all

Infrastructure Security

  • AttestedEncryption in transit enforced
  • AttestedEncryption at rest
  • AttestedTenant data is separated by row-level security in the database
View 7 more Infrastructure Security controls

Organizational Security

  • AttestedSecurity policies established and reviewed
  • AttestedSecurity roles and responsibilities defined
  • AttestedInventory of systems and data assets maintained
View 6 more Organizational Security controls

Internal Security Procedures

  • AttestedIncident response plan established
  • AttestedBreach notification within 72 hours
  • AttestedBusiness continuity and disaster recovery plan established
View 6 more Internal Security Procedures controls

AI Security & Compliance

  • AttestedAI systems are inventoried and described in a published fact sheet
  • AttestedAI use policy published
  • AttestedCustomer data is not used to train models
View 7 more AI Security & Compliance controls

Product Security

  • AttestedMulti-factor authentication available to every account
  • AttestedPasswords stored as salted hashes with rising work factors
  • AttestedSessions in httpOnly, secure cookies with a fixed expiry
View 10 more Product Security controls

Data and Privacy

  • AttestedPrivacy policy published and maintained
  • AttestedData processing addendum available
  • AttestedSub-processor list published with 30 days' notice of change
View 9 more Data and Privacy controls

Data collected

  • Collected:Customer personally identifiable information
  • Collected:Configuration signals from systems a customer connects
  • Not collected:Credit card information
  • Not collected:Personal health information

Subprocessors

View all
Cloudflare, Inc. Edge compute and network security servicesGlobal edge
Core product
WorkOS, Inc. Authentication, single sign-on (SSO), and OAuthUnited States
Core product
Amazon Web Services, Inc. Cloud storage and key managementUnited States and European Union
Core product
Anthropic, PBC Internal-use generative AI for productivityUnited States
Internal tools

Updates

View all

The compliance statements are rewritten, twelve regulatory statements are published, and the compliance list says what each standing is

Compliance

Published September 18, 2026

The eight compliance statements of June were rewritten rather than patched. The earlier set described products Trooth does not have, a mobile application it never shipped and a time-stamping scheme it never built, so correcting the names would have left claims with nothing behind them. Each is re-issued as version 2.0, effective today, without a signature, and describes the company that exists: one product, twelve sub-processors, no payment, no health data.

The policy set is published: nineteen policies and four assurance statements, no signature required

Compliance

Published September 18, 2026

The information security policy set that was available under NDA is now public on the Resources tab, as nineteen numbered policies (POL-01 to POL-19) that take effect as published statements of the company rather than as signed documents. The signed set of 2026-05-25 is superseded. Four assurance statements join them: access monitoring and logging, automated backup and data retention, encryption in transit and at rest, and a network architecture and data flow disclosure.

The Trust Center is reorganised around controls, resources and evidence

General

Published September 18, 2026

This page now lists the controls Trooth attests to in six categories, each with the evidence behind it, and names the controls Trooth does not have yet rather than leaving them out. Resources are grouped by topic with their access level shown; the sub-processor tab reads from the published sub-processor list so the two cannot differ; and the page gains subscriptions, a question form and an access request that a person answers within two business days.

Tenant isolation proven against a live deployment with real sessions

Security

Published September 17, 2026

A harness that signs in as three real accounts in three workspaces and sends each one foreign and forged identifiers into every covered surface ran green against a production-configured deployment. Its earlier runs found three things, each fixed the same day: a refusal returned in the wrong order, a refusal reported as an outage in a notification email, and a forged identifier answered with a server error instead of a not-found. The harness now insists on the right answer in each case.

Request documents under NDA

The risk register, the asset inventory, the records of processing, the impact assessment, the incident response runbook, the continuity plan and the internal retention schedule are shared with customers and qualified prospects under a mutual non-disclosure agreement. A person reviews every request and replies within two business days with the documents and the NDA for signature.