A standard that only its author can check is not a standard. What follows is the whole mechanism: how identity is established, how a fact gets onto a page and what has to be true for it to stay there, how the order of a list is decided, and what happens when a company says we got it wrong.
Identity comes first and it is separate from everything else. A named human is confirmed and control of the domain is shown before a single fact is attached to a company. Without that step every later claim is about a subject nobody has pinned down.
After that, Trooth reads the company’s own live systems on a schedule and records what it saw: the value, the source it came from, and the moment it was read. That triple is the unit. A value without its source is a rumour, and a value without its date is a claim about a past nobody specified.
Each kind of claim runs on its own clock, because facts decay at different rates. Transport configuration can change between lunch and dinner; a certificate’s scope holds for a year. Checking both hourly would waste the company’s systems; checking both annually would publish something false for months.
Every pass is hashed into a ledger that links to the one before it, and the chain is anchored daily. That is what makes history checkable rather than merely asserted: if a reading were quietly changed after the fact, the chain would no longer agree with itself, and anyone can run that check without asking us.
Eight stages, each consuming the one before it. Nothing gets ahead of the evidence, and every stage is something you can check on a company’s page.
One record per company, not one per spelling of its name. Domains, products, and corporate relationships resolve to a single subject before anything is written about it, because two half-records are worse than none: a buyer reads one and misses the other.
Everything that arrives - witnessed, declared, or observed from outside - lands as a dated, labeled record. Nothing is merged into a summary at this stage. The label and the date survive to the page.
Signals are derived per dimension, never rolled into one number. A company can be strong on transport security and silent on subprocessors, and a single score would hide exactly the thing a reader needed.
Results order on published facts and on what the buyer said they require. Payment is not an input, and there is no field in the system where it could be one.
Every fact carries the moment it was last checked and the cadence it is checked on. A reading past its window is labeled stale and stays visible. Hiding a stale fact would leave the reader with the impression it was still true.
Search, the API, and the network directory read the same records and answer with citations. Three surfaces that could disagree would each need its own trust; one record answering three ways needs it once.
Side by side on the same questions, with the differences and the unknowns both shown. A comparison that quietly drops an unanswered question is a comparison that flatters whoever did not answer.
The reader decides. Trooth publishes what is true and what is missing, and stops there. A verdict would make the record about our judgement rather than the evidence.
A page that presents a company’s own description and a reading from its servers in the same voice has destroyed the difference that made the reading worth anything.
Trooth confirms identity and witnesses facts. It does not attest, certify, endorse, or rank editorially, and the advisory on every profile says exactly that: Trooth does not attest, certify, or sign on a company's behalf.
Under the four kinds of claim, each individual fact carries one word from a closed vocabulary. Ten words, the same ten everywhere, so a reader learns them once and never has to guess what a new one means.
Trooth witnessed
Trooth read this directly from the company's connected systems and signed a receipt for what it saw.
Continuously observed
Trooth re-checks this on a schedule; the stamp shows the last pass and the cadence.
Integration supplied
A connected third-party tool reported this through a read-only integration.
Independent third-party
An independent party (an auditor, an issuer, a registry) published this evidence.
Vendor declared
The company stated this about itself. Declared facts are labeled, never blended with witnessed ones.
Public-source
Observed from public records or the company's public surfaces, with the source noted.
Customer reported
Reported by a customer of the company. Reported experience is distinguished from measured data.
Disputed
The company or another party disputes this fact. The dispute and its status are shown, not hidden.
Stale
Past its expected refresh. Trooth keeps it visible and labeled rather than quietly deleting it.
Unknown
Trooth has no evidence either way. Unknown is an answer, never a blank filled in.
Disputed, stale, and unknown are labels, not omissions. A fact past its refresh window stays on the page and says so, and unknown is an answer we publish rather than a blank we fill in.
Live probes re-read hourly. What differs by category is how long the answer still describes the present. One clock for a TLS setting and a funding round would either cry wolf or miss the thing that moved.
| Category | Stale after |
|---|---|
| Connected-system health | 48 hours |
| Operational posture | 48 hours |
| Security configuration | 48 hours |
| AI governance | 7 days |
| Data handling | 7 days |
| Privacy commitments | 7 days |
| Procurement terms | 30 days |
| Product offering | 30 days |
| Customers and partners | 90 days |
| Company identity | 180 days |
| Company history | 1 year |
A declared fact does not go stale by sitting still: the company said it, and they still say it. Only a fact Trooth read for itself carries this clock.
Fourteen categories, and they are not alike. Each one names the information a buyer needs, the deeper evidence a reviewer asks for beyond it, where the values come from, and how long a reading in it counts for.
An unanswered field is published as unanswered. Nothing here blocks a company from publishing: a gap a reader can see is more useful than a record that cannot exist until every box is ticked, which is how records fill with placeholder text.
Asked for beyond the basics: the register's own record, linked, so a reader can go and look; prior names with the dates each was in use, not a present-tense list; which legal entity operates which product.
From: the company's own declaration; a company register record, when one is retrieved.
Ages out under: Company identity.
Asked for beyond the basics: an event's source, where the event was not the company's own announcement; the company's answer beside any event it did not write.
From: the company's own timeline; sourced events recorded against the domain.
Ages out under: Company history.
Asked for beyond the basics: the round, the date and the lead, rather than a total; an undisclosed amount stated as undisclosed rather than omitted.
From: the company's own declaration.
Ages out under: Company history.
Asked for beyond the basics: what a trial or sandbox actually contains, and whether the data in it is synthetic; which products a claim covers, where a claim is not company-wide.
From: the company's own declaration.
Ages out under: Product offering.
Asked for beyond the basics: the unit the price is per, and the currency; what the price was before it moved, and when; which add-ons are separately charged.
From: the company's own declaration; Trooth does not read anybody's pricing page.
Ages out under: Product offering.
Asked for beyond the basics: the publisher and package URL for anything a developer installs; which integrations are built by the company and which by a third party.
From: the company's own declaration; connected build and registry systems, where connected.
Ages out under: Product offering.
Asked for beyond the basics: the penetration test date AND the retest date; a test never re-checked is findings nobody closed; the scope of every certificate, because a report for one product is not a report for four; who holds the encryption keys, and where.
From: connected systems, read on a signed scan; the company's own declaration for anything not connected; certificates and reports, where the company publishes or releases them.
Ages out under: Security configuration.
Asked for beyond the basics: what each class of data is used for, who receives it, and how long it is kept; the route by which a person exercises a right, distinct from a document request.
From: the company's published notice; the company's own declaration.
Ages out under: Privacy commitments.
Asked for beyond the basics: which model provider is behind each feature, and on what terms; whether customer data trains anything, stated per feature rather than once; a provider assurance labelled as the provider's, not as the company's configuration.
From: the company's own declaration; provider system cards and data-use terms, where recorded.
Ages out under: AI governance.
Asked for beyond the basics: per data class: where it is stored, processed, backed up, logged and supported from; whether a failover leaves the chosen region; the law governing the contract, which is not the hosting region.
From: the company's own declaration; connected infrastructure metadata, where connected.
Ages out under: Data handling.
Asked for beyond the basics: the four lanes kept apart: a contractual target, the company's own account, an architecture description, and a reading somebody took; the conditions any measurement was taken under.
From: the company's own declaration; measurements, where any exist.
Ages out under: Operational posture.
Asked for beyond the basics: the term structure, the notice period and what happens to data on exit; whether a quote is buyer-specific, and if so that it never enters public search.
From: the company's own declaration.
Ages out under: Procurement terms.
Asked for beyond the basics: each subprocessor's role and location, not a list of names; the certificate scope for every certification named.
From: the company's own declaration; the company's published subprocessor page, where it has one.
Ages out under: Customers and partners.
Asked for beyond the basics: how the endorser's identity was checked, where it was; whether an incentive was involved.
From: the endorser's own words, approved for publication by the company.
Ages out under: Company history.
Companies with a witnessed page come first, most recently witnessed at the top. Everyone else follows by name. That is the entire rule, and it is a rule precisely so that it can be checked: given the same data, anyone can reproduce the order.
There is no recommended list, no featured slot, and no paid position. Not as a policy we intend to keep, but as an absence: there is no field in the record where a payment could be stored and no term in the ordering where it could be read. A company’s position moves when its evidence moves.
Any company files a dispute from its own profile, claimed or not, pointing at the specific reading it says is wrong.
The signed observation behind that reading is re-run immediately, and the result is published beside the dispute rather than replacing it.
If the re-run contradicts the reading, the record corrects on the next pass and the correction is written to the public ledger, where it stays.
Dispute counts, outcomes, and correction rates are public. A method that demands transparency and audits itself privately is not a method, it is a preference.
A method you can only inspect through our interface is a method you are taking on faith. Everything on a public page is readable as data, by anyone, with no key and no account.
Any company can unpublish its profile at any time, and we will not make it difficult. What unpublishing does not do is remove the outside-in read of the company’s public surface. That refreshes daily and is labeled as unclaimed, because it was never the company’s to publish or withdraw.
So delisting does not remove the page a buyer is already reading. It removes the confirmed identity, the witnessed answers, and the company’s own voice from it. An honest page in repair is a better position than no voice at all, and the checks page names the exact facts to fix next.
Identity is confirmed once: a named human, and domain control shown. Facts are then witnessed from the company’s live systems, each with a source and an as-of date, and re-checked on that claim’s own cadence. Every pass lands in a hash-linked ledger that is anchored daily, so history can be checked rather than trusted.
The Company Profile is what the company declares about itself, always labeled as its own words. The Trooth Record is what Trooth indexes, observes, and witnesses on its own clock. The company cannot write, buy, or edit the record, and claiming a page never converts declarations into witnessed facts.
Every fact carries one label from a closed ten-word vocabulary saying where it came from, listed in full above on this page. Disputed, stale, and unknown are labels too: a fact past its refresh stays visible and says so, and unknown is an answer, never a blank filled in.
Every witnessed fact shows its last-witnessed date next to its age. Live probes re-read hourly. Each category then has its own refresh window, published in the table on this page: 48 hours for security, operational posture and connected-system health, longer for the things that genuinely change slowly. Past its own window a fact is labeled stale rather than quietly kept green.
No. Directory ordering is a mechanical fact: witnessed pages first, most recently witnessed at the top, then everyone else by name. There is no paid placement, no pay-to-pass, and no sponsored ranking. If Trooth ever charges, it will charge for tools that help a company improve what is true, never for the record of what is true.
Create an account, find your company, and claim it. Claiming lets you add declared fields and connect your stack for witnessing; it never removes history or rewrites what Trooth observed before you arrived.
Identity confirmed, facts witnessed with dates, the same cadence and the same labels. A standard whose author is exempt from it is a sales document.