Skip to main content

Trooth Trust Center

Public documents are available for download. Confidential documents are shared with customers and qualified prospects under a mutual NDA.

Compliance & Frameworks

Active today

  • GDPRAligned
  • NIST CSFAligned
  • DORAAligned
  • EU AI ActAligned
  • VPATSelf-attested

Self-attested and framework-aligned. Backed by our own controls and documentation; not an independent certification.

On our roadmap

  • SOC 2 Type IIOn our roadmap
  • SOC 3On our roadmap
  • ISO 27001On our roadmap
  • ISO 27701On our roadmap
  • ISO 42001On our roadmap

Our controls are operating today and we are audit-ready. These require an independent audit we are preparing for; the formal third-party assessment is on our roadmap.

Trooth shows what is witnessed and self-attested, and is transparent about what is still on the roadmap.

How Trooth secures Trooth

The platform that witnesses other companies' controls runs its own the same way. Two-factor authentication (authenticator-app TOTP) is built in and free for every account, including buyer accounts. It is a property of having a Trooth login, never a paid feature. Enable it in Settings. Passwords are stored as salted PBKDF2 hashes and upgraded transparently as work factors rise; sign-in and signup are hardened against account enumeration with equalized timing and lockout on repeated failures. Sessions live in httpOnly cookies with a 30-day absolute expiry. API keys are shown once and stored only as SHA-256 hashes, revocable at any time. Every API request is tenant-scoped; every material action lands in the signed, hash-linked audit ledger. Trooth takes no payment and holds no card data. These statements are self-attested and, where the code is involved, verifiable in conduct: the same behaviors are observable from the outside on every login and key.

Data residency

Where your data lives. Trooth runs entirely on managed cloud infrastructure. Primary data is stored in the United States, with EU-region processing available for EU customers on request. Edge compute and content delivery run globally via Cloudflare. Our current sub-processor list, with each provider's purpose and processing region, is published in this Trust Center and updated when it changes. Trooth does not sell customer data and does not use customer data to train AI models.

Public documents

Available for immediate download. No NDA required.

  • Trust & Security Program Summary

    Our security, governance, privacy, and compliance program at a glance.

    Open PDF
  • Security Overview

    How Trooth protects your data.

    Open PDF
  • Security, Privacy & Compliance Self-Assessment (CAIQ / SIG)

    Our completed self-assessment.

    Open PDF
  • Shared Responsibility Model

    Who secures what.

    Open PDF
  • Sub-Processor Register

    Our third-party providers.

    Open PDF
  • Vulnerability Disclosure Policy

    How to report a vulnerability.

    Open PDF
  • EU AI Act Transparency & Risk Classification

    Our AI compliance.

    Open PDF
  • AI System Fact Sheet (Model Card)

    What our AI does and its limits.

    Open PDF
  • Data Subject Rights Request Procedure

    Exercise your privacy rights.

    Open PDF
  • Trust Center Document Index

    The full list of available materials.

    Open PDF

Available under NDA

These confidential documents are shared with customers and qualified prospects under a mutual non-disclosure agreement. They are not publicly downloadable.

  • ISMS Policy Manual

    18 security policies.

    Request under NDA
  • Statement of Applicability

    ISO/IEC 27001 control applicability.

    Request under NDA
  • Information Security Risk Register

    Tracked risks, owners, and treatment.

    Request under NDA
  • Information Asset Inventory

    Cataloged systems and data assets.

    Request under NDA
  • Records of Processing Activities (RoPA)

    GDPR Article 30 processing records.

    Request under NDA
  • Data Protection Impact Assessment (DPIA)

    Risk assessment for high-risk processing.

    Request under NDA
  • Incident Response Plan

    Detection, classification, and notification process.

    Request under NDA
  • Business Continuity & Disaster Recovery Plan

    Resilience, RPO, and RTO targets.

    Request under NDA
  • Data Retention & Disposal Schedule

    Retention periods and secure disposal.

    Request under NDA
  • Completed SIG Lite workbook

    Standardized Information Gathering responses.

    Request under NDA

Request documents under NDA

Tell us who you are and what you need. We respond within two business days with the requested documents and an NDA for execution.

Documents requested *

0/500