Trooth Trust Center
Public documents are available for download. Confidential documents are shared with customers and qualified prospects under a mutual NDA.
Compliance & Frameworks
Active today
- GDPRAligned
- NIST CSFAligned
- DORAAligned
- EU AI ActAligned
- VPATSelf-attested
Self-attested and framework-aligned. Backed by our own controls and documentation; not an independent certification.
On our roadmap
- SOC 2 Type IIOn our roadmap
- SOC 3On our roadmap
- ISO 27001On our roadmap
- ISO 27701On our roadmap
- ISO 42001On our roadmap
Our controls are operating today and we are audit-ready. These require an independent audit we are preparing for; the formal third-party assessment is on our roadmap.
Trooth shows what is witnessed and self-attested, and is transparent about what is still on the roadmap.
How Trooth secures Trooth
The platform that witnesses other companies' controls runs its own the same way. Two-factor authentication (authenticator-app TOTP) is built in and free for every account, including buyer accounts. It is a property of having a Trooth login, never a paid feature. Enable it in Settings. Passwords are stored as salted PBKDF2 hashes and upgraded transparently as work factors rise; sign-in and signup are hardened against account enumeration with equalized timing and lockout on repeated failures. Sessions live in httpOnly cookies with a 30-day absolute expiry. API keys are shown once and stored only as SHA-256 hashes, revocable at any time. Every API request is tenant-scoped; every material action lands in the signed, hash-linked audit ledger. Trooth takes no payment and holds no card data. These statements are self-attested and, where the code is involved, verifiable in conduct: the same behaviors are observable from the outside on every login and key.
Data residency
Where your data lives. Trooth runs entirely on managed cloud infrastructure. Primary data is stored in the United States, with EU-region processing available for EU customers on request. Edge compute and content delivery run globally via Cloudflare. Our current sub-processor list, with each provider's purpose and processing region, is published in this Trust Center and updated when it changes. Trooth does not sell customer data and does not use customer data to train AI models.
Public documents
Available for immediate download. No NDA required.
- Open PDF
Trust & Security Program Summary
Our security, governance, privacy, and compliance program at a glance.
- Open PDF
Security Overview
How Trooth protects your data.
- Open PDF
Security, Privacy & Compliance Self-Assessment (CAIQ / SIG)
Our completed self-assessment.
- Open PDF
Shared Responsibility Model
Who secures what.
- Open PDF
Sub-Processor Register
Our third-party providers.
- Open PDF
Vulnerability Disclosure Policy
How to report a vulnerability.
- Open PDF
EU AI Act Transparency & Risk Classification
Our AI compliance.
- Open PDF
AI System Fact Sheet (Model Card)
What our AI does and its limits.
- Open PDF
Data Subject Rights Request Procedure
Exercise your privacy rights.
- Open PDF
Trust Center Document Index
The full list of available materials.
Available under NDA
These confidential documents are shared with customers and qualified prospects under a mutual non-disclosure agreement. They are not publicly downloadable.
- Request under NDA
ISMS Policy Manual
18 security policies.
- Request under NDA
Statement of Applicability
ISO/IEC 27001 control applicability.
- Request under NDA
Information Security Risk Register
Tracked risks, owners, and treatment.
- Request under NDA
Information Asset Inventory
Cataloged systems and data assets.
- Request under NDA
Records of Processing Activities (RoPA)
GDPR Article 30 processing records.
- Request under NDA
Data Protection Impact Assessment (DPIA)
Risk assessment for high-risk processing.
- Request under NDA
Incident Response Plan
Detection, classification, and notification process.
- Request under NDA
Business Continuity & Disaster Recovery Plan
Resilience, RPO, and RTO targets.
- Request under NDA
Data Retention & Disposal Schedule
Retention periods and secure disposal.
- Request under NDA
Completed SIG Lite workbook
Standardized Information Gathering responses.
Request documents under NDA
Tell us who you are and what you need. We respond within two business days with the requested documents and an NDA for execution.