Skip to main content

What shipped, dated.

Changes that affect what Trooth witnesses, confirms, or publishes, recorded as they land, not marketed after the fact. If a change alters how a count on this platform is measured, it belongs here.

2026-09-04

The 0-100 standing is deleted

Trooth no longer computes, stores, or publishes a single number summarising a company. It is deleted, not hidden: the planner that ranked moves by what each was worth, the page that published the formula, the ring on the badge image, the figure in the embed a vendor pastes on its own site, the number in weekly digests and re-review reminders and calendar events, and the stored column behind each of them are all gone. What remains is what was always underneath: which checks passed, out of how many were run, in which areas, on what date, and whether a company is witnessed at all. The directory is ordered by witnessed state and by how recent the evidence is, never by a standing. Everything Trooth shows you now is something it measured.

2026-08-02

Launch: the Trooth Network is open

The Trooth Network is live. Any company can claim a free profile and be witnessed hourly from signed evidence, and any buyer can look up a vendor's real posture before a call. This release also hardened the platform for public traffic: every call to the upstream witness API now carries a hard timeout so one slow dependency can never take the site down, the routes that send email or cost money are rate limited, and upstream failures now report to error monitoring instead of degrading silently. Transactional email moved to a single house template, so every message from Trooth carries the same crosshair mark, wordmark, palette, and plain-text alternative. Accessibility improved across the public directory: the trust status labels now meet WCAG AA contrast at a readable size, and every search and form field carries an accessible name.

2026-07-25

Register views, severity-true sorting, CSV evidence exports

Every register in the dashboard (API keys, people, policies, AI inventory, vendors, and Guard datasets) now shares one table system with saved views, column control, and sortable headers. Sorting is severity-true where alphabetical order would lie: EU AI Act risk classes rank unacceptable first, vendor criticality ranks critical first. Any view exports to CSV exactly as displayed, so the register an auditor receives is the register you see. The dashboard also gained keyboard navigation: press ? anywhere for the shortcut map.

2026-07-24

MCP server, incident ledger, ML-BOM export, Guard policy center

Trooth's public trust layer is now queryable by AI agents over the Model Context Protocol at api.trooth.co/public/mcp: published profiles, live outside-in reads, and the knowledge base, read-only with no key. A public append-only incident ledger opened at /incidents, and this changelog opened with it. The AI inventory exports a CycloneDX 1.6 ML-BOM, and Trooth Guard gained a per-tenant screening policy: family toggles plus custom deny terms.

2026-07-24

API keys, live outside-in reads, dispute path, /verify

Revocable tenant API keys (secret shown once, hash-only storage) now authenticate every /v1 endpoint. Unclaimed company pages read TLS, security headers, and security.txt live on every view instead of showing placeholders. Anything Trooth publishes can now be disputed at /network/dispute, and /verify collects every independent check in one place. This release also shipped a planning tool built around the 0-100 standing, which was deleted on 2026-09-04 along with the standing itself.

2026-07-24

People, Access Reviews, policy acceptance, Auditor Portal, vendor-network standing

Personnel lifecycle with onboarding/offboarding checklists, device attestation (labeled self-attested), and training records. User-access-review campaigns with auto-flagged admin/former-personnel/no-MFA rows and evidence export. Typed-name policy acceptance links. Read-only auditor portals with logged visits and evidence requests. Vendor rows now show each vendor's live witnessed standing on the Trooth Network.

2026-07-23

Trooth Network on real directory data

The public Network reads the live directory and signed scan results, so nothing on a company page is entered by hand. Canonical company pages at /network/{domain}; the trust badge loader moved to trooth.co/badge.js for reliability.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Methodology changes are additionally documented on the methodology page. Incidents live on their own ledger.