Skip to main content

Resolve a company, not just a domain.

The Domain Name System (DNS) tells you where a company is. A certificate tells you the connection is real. Neither tells you who you are dealing with. One command in the Trooth command-line interface (CLI), a tool you run in a terminal, reads the record the Trooth Network publishes: who they are, what was witnessed and what they attested, each dated, and the signature behind it.

# No install, no key. Read a company by domain.npx trooth check trooth.co# Abbreviated, with illustrative values. Each line is one the CLI prints.Trooth Network // public record · read-only //Trooth, LLC   trooth.coListing state: listed; Trooth witnessed a reading   reading dated 2026-09-26   first published 2026-08-01Live probes: 65 read; 63 as expectedSelf-attestations: 35 asked; 27 attestedBadge rw_...   Key trooth-master-2026-09This command did not check the record's signature. The signature covers thereading, not every fact on the company's profile. To check it yourself: https://trooth.co/docs/verifiable-evidenceA dated, point-in-time record. Trooth issues no verdict and no single number.
A domain
Input
None
Credential
Node 18+, one pinned dep
Runtime

What it does

It reads a record.It does not grade one.

It says what it sends

check sends one request: the domain you ask about, in the address, plus the IP address and user agent every web request carries. There is no key, no account and no telemetry, and the binary has no write path of any kind. lint sends nothing at all.

It answers in facts, not a number

Witnessed counts and attested counts are printed apart, with the date of the reading and the key that signed it. The CLI does not check that signature and says so. Trooth publishes no grade or rating, and a feed that sent one would have it dropped before printing.

An outage is not a verdict

A company with no record exits 1. A listed company with no witnessed reading exits 5. A Trooth that could not be reached exits 3. A pipeline can tell the three apart without parsing prose, so an outage never reads as a vendor Trooth has not witnessed.

Usage

Three ways to run it.

Same binary in each. One pinned dependency, Node 18 or newer.

Read the CLI docs
# No install, no key, no account. Reads the public record.npx trooth check stripe.com

Exit codes

Six answers, told apart.

Six codes, read out of the binary. A pipeline can tell a company Trooth has not witnessed from a Trooth it could not reach without parsing prose.

  • 00 · listed and witnessedcheck · lint

    check: the Network holds a published record with a dated reading Trooth witnessed, printed with the ids and the key behind it. lint: every selected file was read.

  • 11 · not listedcheck

    The Network was read and holds no record for this company. That is an answer, not a failure, and it is not a statement that the company is untrustworthy.

  • 22 · usagecheck · lint

    A missing argument, an unknown flag or an unreadable path. The message names the flag and lists the ones that exist.

  • 33 · could not readcheck

    Trooth did not answer. Nothing is known about this company right now, and the CLI says so instead of printing “not listed”. A pipeline that treated this as an absent record would fail a build because of a Trooth outage, so it exits distinctly and prints nothing about the company at all.

  • 44 · incomplete readlint

    lint: a file was skipped, could not be parsed or could not be opened, or the walk stopped at its file limit. The counts cover only what was read, and the coverage line says what was not. Pass --allow-incomplete to report the gap and exit 0.

  • 55 · listed, not witnessedcheck

    check: the company is listed, but its record carries no reading the CLI can confirm Trooth witnessed. Being listed is not the same as being witnessed, so it exits apart from 0.

Read what you declare, without sending it anywhere.

trooth lint parses the Terraform, Kubernetes and container files in a directory and prints what they declare: which regions, how many storage resources declare encryption on, off, or not at all, how many rules are open to any address. It says which files it could not read. Then it prints a digest of those counts.

What it deliberately does not do: it issues no verdict, no severity and no rating, and it checks nothing against any named standard. Declaring public ingress is not a failing: a load balancer is supposed to be public. What the facts mean is your decision, not Trooth's.

# Entirely local. No key, no network, no upload.trooth lint tests/fixtures/infra# The two-file fixture in the trooth-cli repository.trooth lint // local · offline · declarations only //tests/fixtures/infra   2 declaration file(s) readterraform 1 · kubernetes 1 Declared  Regions and zones                        us-east-1  Storage declarations                     1    declaring encryption                   1    declaring encryption off               0    declaring nothing about encryption     0    set by an unresolved expression        0  Logging declarations                     0  Identity declarations                    0  Open to any address (0.0.0.0/0, ::/0)    1  Marked public                            0  Inline credential literals               0 Most declared resource types     1  aws_s3_bucket     1  aws_s3_bucket_server_side_encryption_configuration     1  aws_security_group_rule     1  Deployment Coverage  complete  2 selected: 2 read, 0 not declarations, 0 excluded, 0 skipped, 0 invalid, 0 unreadable. Facts digest  sha256:2ba1da28be9e97e1e8be1f7e41641288bc632192c062ba1fbd563350448fd5a8A SHA-256 over the counts above, in canonical form. It is an aggregate: two differenttrees with the same counts share it. It does not identify your files, your repositoryor a deployment. How this was read  Every file is parsed; a file that does not parse is reported as invalid, not read.  Comments count for nothing. Nothing is evaluated: a setting that depends on a variable,  a local, a module or a function is reported as unresolved. Dockerfiles: ENV and ARG only. Counts of what the files declare. Not a judgment: a public load balancer issupposed to be public. Trooth issues no verdict here and checks nothing againstany standard. Nothing left this machine: lint opens files and opens no sockets.Publish what you choose on your record at https://trooth.co/dashboard.# Keep the facts as a build artifact.trooth lint --json > trooth-lint.json

Your own infrastructure

It opens files and opens no sockets.

No file name, no line, no code and no value is transmitted. The digest is an aggregate over the counts: two trees with the same counts share it, so it records what was counted without identifying the tree it came from. Record it in your continuous integration (CI) pipeline, or in your own records. With --json, it prints the same facts and digest as one JavaScript Object Notation (JSON) document instead.

Four ways in. One record behind all of them.

The CLI, the public application programming interface, the Model Context Protocol server for AI agents and the webhooks all read the record the Network publishes. They are interfaces to it, not separate products. Trooth signs the witness statement for each reading; the company-declared facts beside it are not signed.

View as agent