Skip to main content

The rulebooks the witness reads against.

Trooth is where companies are confirmed. Confirmed: who they are. Witnessed: what's true about them. A framework here is not the product, it is the rulebook we read your witnessed facts against, so every claim carries a receipt with a source and an as-of date.

10Frameworks
1Witness reads all
1 free scan
witnesses coverage across
SOC 2
ISO 27001
ISO 42001
GDPR
HIPAA
NIST AI RMF
EU AI Act
PCI DSS
CCPA
NIST CSF 2.0

The rulebooks we read against.

Each one read from the same witnessed facts. Six have a detail page naming what is witnessed and what is not; the rest are covered by the scan today.

01

SOC 2 for AI Vendors

The trust standard for SaaS. SOC 2 Type II proves you have controls for security, availability, processing integrity, confidentiality, and privacy.

What Trooth witnesses for SOC 2
What we map
  • Security controls (encryption, access, audit logging)
  • Availability monitoring (uptime, incident response)
  • Processing integrity (data validation, error handling)
  • Privacy commitments (DPA, retention, deletion)
The receipt: Encryption, access, and logging facts witnessed with a source and an as-of date, read against the SOC 2 criteria
02

ISO 27001 for AI Vendors

The international standard for information security management. ISO 27001 opens doors with EU buyers and regulated industries.

What Trooth witnesses for ISO 27001
What we map
  • Annex A control coverage
  • Risk treatment plans
  • Asset inventory (model artifacts, training data)
  • Supplier relationships (sub-processor cascade)
The receipt: Annex A signals witnessed from your live stack and dated, in a form your ISO auditor can read
03Aug 2, 2026

EU AI Act, Article 50

Enforcement began August 2, 2026. If you sell AI to anyone in the EU, you need a conformity assessment, transparency disclosures, and risk classification.

What Trooth witnesses for EU AI Act
What we map
  • Article 50 transparency obligations
  • High-risk AI system classification
  • Conformity assessment readiness
  • Post-market monitoring + drift detection
The receipt: Transparency disclosures witnessed and republished with dates, so drift is visible; deep EU AI Act governance on Dossier
04

NIST AI RMF 1.0

The US National Institute of Standards' AI Risk Management Framework. Voluntary today. Required for federal AI vendors soon. Buyers use it as a procurement checklist.

What Trooth witnesses for NIST AI RMF 1.0
What we map
  • Govern: AI governance policies + accountability
  • Map: AI system context + risk identification
  • Measure: bias, safety, security testing
  • Manage: risk treatment + continuous improvement
The receipt: Your Govern, Map, Measure, and Manage disclosures witnessed, each with a source and an as-of date
05

HIPAA for AI in Healthcare

If your AI touches protected health information, you need controls built for HIPAA. Healthcare buyers won't sign without it.

What Trooth witnesses for HIPAA
What we map
  • PHI handling and de-identification
  • Business Associate Agreement (BAA) coverage
  • Audit trail completeness
  • Breach notification readiness
The receipt: Encryption posture, BAA position, and sub-processor facts witnessed and dated, ready for a healthcare buyer to check
06

ISO 42001, AI Management

The first international standard for AI management systems. ISO 42001 shows buyers you govern AI responsibly end to end, the way ISO 27001 did for information security.

What we map
  • AI management system scope + policy
  • AI risk and impact assessments
  • Data governance for training and inference
  • Lifecycle controls (development to decommission)
The receipt: AI governance facts witnessed and dated, in a form your certification body can read
07

GDPR for Software and AI

The EU's data protection regulation. If you process the personal data of anyone in the EU, GDPR governs how, and buyers require a DPA before they sign.

What Trooth witnesses for GDPR
What we map
  • Lawful basis + records of processing (RoPA)
  • Data subject rights (access, erasure, portability)
  • DPA + sub-processor disclosures
  • Breach notification within 72 hours
The receipt: Your DPA position, sub-processor register, and retention practices witnessed, dated when they last changed
08

PCI DSS for Payments

The security standard for handling cardholder data. If your software touches payments, PCI DSS is non-negotiable for your processor and your customers.

What we map
  • Cardholder data scope + network segmentation
  • Encryption of cardholder data in transit and at rest
  • Access control + continuous monitoring
  • Quarterly vulnerability scanning readiness
The receipt: Encryption and access facts witnessed and dated, read against PCI DSS requirements
09

CCPA for US Privacy

California's consumer privacy law, extended by CPRA. It reaches most software companies with US customers, and enterprise buyers expect you to help them meet it.

What we map
  • Consumer rights (know, delete, correct, opt out)
  • Do-not-sell and do-not-share handling
  • Data inventory + retention limits
  • Service-provider contract terms
The receipt: Privacy disclosures and retention practices witnessed and dated, read against CCPA and CPRA
10

NIST CSF 2.0

The US Cybersecurity Framework, updated in 2024 with a Govern function. Buyers and public-sector procurement use it as a common security baseline.

What we map
  • Govern: cybersecurity strategy + oversight
  • Identify and Protect: assets, access, data security
  • Detect and Respond: monitoring + incident response
  • Recover: continuity + restoration
The receipt: Witnessed security facts with dates, mapped across the CSF functions from Govern to Recover

One control, many frameworks.

SOC 2, ISO 27001, ISO 42001, GDPR, and the rest restate a great many of the same underlying controls. We witness each fact once, with its source and date, then map that one receipt across every rulebook it meets.

Encryption at rest + in transit
covers SOC 2 CC6, ISO A.10, HIPAA §164.312(a)(2)(iv), and more
Sub-processor cascade
covers ISO A.15, SOC 2 CC9, EU AI Act Annex IV
Drift monitoring
covers NIST AI RMF Manage, SOC 2 CC7, EU AI Act post-market obligations

Every claim carries a receipt.

Every framework mapping here is free, for every company, with no plan to pick and nothing to buy. Each mapping reads from the same witnessed facts, each re-read on its own published window, and every fact carries its source and the date it was last checked.

Claim your company page