The Trooth Network: the witnessed trust network for software and AI companies.
Browse the Network · Join the Network · How witnessing works · Docs · Pricing
Every company on the Trooth Network has a public trust profile built from witnessed evidence: real security, compliance, and AI-governance posture, observed from live systems, signed and timestamped, and kept current automatically. Buyers read and compare it with no login. No self-marked questionnaires. No pay-for-a-badge.
Trooth automates. Trooth never signs. Your systems produce the evidence; Trooth witnesses it and shows the source and timestamp of every claim. Nothing on the Network is certified, guaranteed, or taken on anyone's word, including ours.
| You are | What the Network does for you |
|---|---|
| An indie founder | A public trust profile that answers "can we trust this vendor?" before you can afford a security team, and a listing in a directory buyers actually search. |
| A startup | Witnessed security posture that turns weeks of enterprise security review into a link. Send a profile, not a 300-row spreadsheet. |
| A mid-size company | Compliance posture mapped to SOC 2, ISO 27001, the EU AI Act, NIST AI RMF, GDPR, and HIPAA, with drift surfaced when it happens, not at audit time. |
| An enterprise | Every vendor evaluated on the same witnessed evidence, side by side. Require Trooth across your vendor list and stop chasing PDFs. |
Marketing, exposure, security posture, compliance posture: one profile carries all four, because all four come from the same witnessed evidence.
The Network directory is public and free. Search it, open any profile, compare vendors, and request locked documents under NDA, all without creating an account. Start at trooth.co/network or see how buyers use Trooth.
The Trooth platform is proprietary. What we open-source is everything a third party needs to verify Trooth-issued artifacts and integrate Trooth into their own stack. All public repositories are Apache 2.0.
| Repo | Purpose |
|---|---|
trooth-platform |
The canonical developer platform: OpenAPI 3.1 spec, architecture, and copy-paste examples (cURL, Node, Python, Go) across the PROTECT, PROVE, and GROW capabilities. |
trooth-templates |
Open-source compliance templates: Privacy Policy, ToS, AUP, AI Use Policy, Model Card, security.txt, SBOM, and AI-code disclosure. |
trooth-action |
GitHub Action that runs Trooth compliance scans on every push. Free for public repos. |
trooth-cli |
Run scans, verify Trust Receipts, and check your Trust Score from the terminal. Build from source today; the npm release is in progress. |
trust-verifier-sdk |
Independently verify any Trooth Trust Receipt without trusting Trooth, against the published keys at trooth.co/verify/keys. |
trooth-vscode |
VS Code and Cursor extension: run scans, check drift, and verify Trust Receipts without leaving your editor. |
trooth-eval-harnesses |
Compliance evaluation harnesses for NIST CSF 2.0, NIST AI RMF 1.0, the EU AI Act, GDPR, and CCPA. |
See the Vulnerability Disclosure Policy and /.well-known/security.txt. Our own posture is documented at trooth.co/security, witnessed the same way every other company on the Network is.
General: hello@trooth.co ▪ Security: security@trooth.co ▪ Legal: legal@trooth.co ▪ Privacy: privacy@trooth.co
// BUILT FOR YOU, NOT OFF YOU //
© 2026 Trooth, LLC ▪ Miami, Florida ▪ Trooth automates. Trooth never signs.