Skip to main content
Skip to main content
Trust Center

Trooth

Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. Companies connect their systems, Trooth records what it observed of them and when, and buyers read the record with its sources and timestamps. This page is Trooth's own record, held to the same standard Trooth asks of every company on the Trooth Network. Trooth, LLC is a Florida limited liability company (L25000561494) based in Miami.

Compliance

Aligned, on our roadmap

Not applicable

Resources

View all

Compliance

Policies

Security

AI Governance

Regulatory

Controls

Updated September 23, 2026
View all

Infrastructure Security

  • AttestedEncryption in transit enforced
  • AttestedEncryption at rest
  • AttestedTenant data is separated by row-level security in the database
View 7 more Infrastructure Security controls

Organizational Security

  • AttestedSecurity policies established and reviewed
  • AttestedSecurity roles and responsibilities defined
  • AttestedInventory of systems and data assets maintained
View 6 more Organizational Security controls

Internal Security Procedures

  • AttestedIncident response plan established
  • AttestedBreach notification within 72 hours
  • AttestedBusiness continuity and disaster recovery plan established
View 6 more Internal Security Procedures controls

AI Security & Compliance

  • AttestedAI systems are inventoried and described in a published fact sheet
  • AttestedAI use policy published
  • AttestedCustomer data is not used to train models
View 7 more AI Security & Compliance controls

Product Security

  • AttestedMulti-factor authentication available to every account
  • AttestedPasswords stored as salted hashes with rising work factors
  • AttestedSessions in httpOnly, secure cookies with a fixed expiry
View 10 more Product Security controls

Data and Privacy

  • AttestedPrivacy policy published and maintained
  • AttestedData processing addendum available
  • AttestedSub-processor list published with 30 days' notice of change
View 9 more Data and Privacy controls

Data collected

  • Collected:Customer personally identifiable information
  • Collected:Configuration signals from systems a customer connects
  • Not collected:Credit card information
  • Not collected:Personal health information

Sub-processors

View all
Cloudflare, Inc. Edge compute and network security services, form bot checks (Turnstile), and AI inference (Workers AI) for the Kyrie assistant and questionnaire draftingGlobal edge
Core product
WorkOS, Inc. Authentication, single sign-on (SSO), and OAuthUnited States
Core product
Amazon Web Services, Inc. Cloud storage and key managementUnited States and European Union
Core product
Anthropic, PBC Internal-use generative AI for productivityUnited States
Internal tools

Updates

View all

The change-control description is corrected to what the deploy workflow enforces

Security

Published September 23, 2026

The control for production deploys said that direct deploys from a laptop were refused by the workflow's own checks. The workflow has no such check, so the sentence was withdrawn. The control now says what holds: the routine path is the GitHub Actions workflow, which does not upload until every build gate succeeds; the gates are also part of the build command, so a build made with the project's configuration runs them; and nothing refuses a deploy made outside GitHub by someone holding the hosting account's deploy token, so access to production rests on who holds that token.

The compliance statements are rewritten, twelve regulatory statements are published, and the compliance list says what each record is

Compliance

Published September 18, 2026

The eight compliance statements of June were rewritten rather than patched. The earlier set described products Trooth does not have, a mobile application it never shipped and a time-stamping scheme it never built, so correcting the names would have left claims with nothing behind them. Each is re-issued as version 2.0, effective today, without a signature, and describes the company that exists: one product, twelve sub-processors, no payment, no health data.

The policy set is published: nineteen policies and four assurance statements, no signature required

Compliance

Published September 18, 2026

The information security policy set that was available under NDA is now public on the Resources tab, as nineteen numbered policies (POL-01 to POL-19) that take effect as published statements of the company rather than as signed documents. The signed set of May 25, 2026 is superseded. Four assurance statements join them: access monitoring and logging, automated backup and data retention, encryption in transit and at rest, and a network architecture and data flow disclosure.

The Trust Center is reorganized around controls, resources and evidence

General

Published September 18, 2026

This page now lists the controls Trooth states it has in place, in six categories, each with the evidence behind it, and names the controls Trooth does not have yet rather than leaving them out. Resources are grouped by topic with their access level shown; the sub-processor tab reads from the published sub-processor list so the two cannot differ; and the page gains subscriptions, a question form and an access request that a person answers within two business days.

Request documents under NDA

The risk register, the asset inventory, the records of processing, the impact assessment, the incident response runbook, the continuity plan and the internal retention schedule are shared with customers and qualified prospects under a mutual non-disclosure agreement. A person reviews every request and replies within two business days with the documents and the NDA for signature.

View as agent