The rulebooks the witness reads against.
Trooth is where companies are confirmed. Confirmed: who they are. Witnessed: what's true about them. A framework here is not the product, it is the rulebook we read your witnessed facts against, so every claim carries a receipt with a source and an as-of date.
The rulebooks we read against.
Each one read from the same witnessed facts. Six have a detail page naming what is witnessed and what is not; the rest are covered by the scan today.
SOC 2 for AI Vendors
The trust standard for SaaS. SOC 2 Type II proves you have controls for security, availability, processing integrity, confidentiality, and privacy.
What Trooth witnesses for SOC 2- Security controls (encryption, access, audit logging)
- Availability monitoring (uptime, incident response)
- Processing integrity (data validation, error handling)
- Privacy commitments (DPA, retention, deletion)
ISO 27001 for AI Vendors
The international standard for information security management. ISO 27001 opens doors with EU buyers and regulated industries.
What Trooth witnesses for ISO 27001- Annex A control coverage
- Risk treatment plans
- Asset inventory (model artifacts, training data)
- Supplier relationships (sub-processor cascade)
EU AI Act, Article 50
Enforcement began August 2, 2026. If you sell AI to anyone in the EU, you need a conformity assessment, transparency disclosures, and risk classification.
What Trooth witnesses for EU AI Act- Article 50 transparency obligations
- High-risk AI system classification
- Conformity assessment readiness
- Post-market monitoring + drift detection
NIST AI RMF 1.0
The US National Institute of Standards' AI Risk Management Framework. Voluntary today. Required for federal AI vendors soon. Buyers use it as a procurement checklist.
What Trooth witnesses for NIST AI RMF 1.0- Govern: AI governance policies + accountability
- Map: AI system context + risk identification
- Measure: bias, safety, security testing
- Manage: risk treatment + continuous improvement
HIPAA for AI in Healthcare
If your AI touches protected health information, you need controls built for HIPAA. Healthcare buyers won't sign without it.
What Trooth witnesses for HIPAA- PHI handling and de-identification
- Business Associate Agreement (BAA) coverage
- Audit trail completeness
- Breach notification readiness
ISO 42001, AI Management
The first international standard for AI management systems. ISO 42001 shows buyers you govern AI responsibly end to end, the way ISO 27001 did for information security.
- AI management system scope + policy
- AI risk and impact assessments
- Data governance for training and inference
- Lifecycle controls (development to decommission)
GDPR for Software and AI
The EU's data protection regulation. If you process the personal data of anyone in the EU, GDPR governs how, and buyers require a DPA before they sign.
What Trooth witnesses for GDPR- Lawful basis + records of processing (RoPA)
- Data subject rights (access, erasure, portability)
- DPA + sub-processor disclosures
- Breach notification within 72 hours
PCI DSS for Payments
The security standard for handling cardholder data. If your software touches payments, PCI DSS is non-negotiable for your processor and your customers.
- Cardholder data scope + network segmentation
- Encryption of cardholder data in transit and at rest
- Access control + continuous monitoring
- Quarterly vulnerability scanning readiness
CCPA for US Privacy
California's consumer privacy law, extended by CPRA. It reaches most software companies with US customers, and enterprise buyers expect you to help them meet it.
- Consumer rights (know, delete, correct, opt out)
- Do-not-sell and do-not-share handling
- Data inventory + retention limits
- Service-provider contract terms
NIST CSF 2.0
The US Cybersecurity Framework, updated in 2024 with a Govern function. Buyers and public-sector procurement use it as a common security baseline.
- Govern: cybersecurity strategy + oversight
- Identify and Protect: assets, access, data security
- Detect and Respond: monitoring + incident response
- Recover: continuity + restoration
One control, many frameworks.
SOC 2, ISO 27001, ISO 42001, GDPR, and the rest restate a great many of the same underlying controls. We witness each fact once, with its source and date, then map that one receipt across every rulebook it meets.
Every claim carries a receipt.
Every framework mapping here is free, for every company, with no plan to pick and nothing to buy. Each mapping reads from the same witnessed facts, each re-read on its own published window, and every fact carries its source and the date it was last checked.
Claim your company page