We build cryptographic compliance infrastructure for AI products. Continuous monitoring against SOC 2, ISO 27001, EU AI Act, NIST AI RMF, and HIPAA. Daily-anchored audit chains. Multi-party approval. A public Trust Profile. Independently verifiable receipts.
Our promise: Trooth automates. Trooth never signs. Your key signs your claim. Our key witnesses that you did. Two roles, mathematically separate.
This organization hosts our open-source libraries, integration tooling, and reference implementations. The Trooth platform itself is proprietary; what we open-source is everything a third party needs to verify Trooth-issued artifacts and integrate Trooth into their own stack.
| Repo | Purpose |
|---|---|
trooth-platform |
Canonical developer platform: the OpenAPI 3.1 spec, architecture, and copy-paste examples (cURL, Node, Python, Go) across all nine PROTECT / PROVE / GROW capabilities. |
trooth-templates |
Open-source compliance templates: Privacy Policy, ToS, AUP, AI Use Policy, Model Card, security.txt, SBOM, AI-Code disclosure. |
trooth-action |
GitHub Action to run Trooth compliance scans on every push. Free for public repos. |
trooth-cli |
Run compliance scans, verify Trust Receipts, and check status from your terminal. Free at the Bronze tier via npm. |
trust-verifier-sdk |
Independently verify any Trust Receipt without trusting Trooth. Ed25519 and RFC 3161 verification against our published keys. |
trooth-vscode |
VS Code and Cursor extension. Run compliance scans, check drift, and verify Trust Receipts without leaving your editor. |
trooth-eval-harnesses |
Open-source compliance evaluation harnesses for NIST CSF 2.0, NIST AI RMF 1.0, EU AI Act, GDPR, and CCPA. |
All repositories are Apache 2.0 licensed. Cryptographic verification ships with the production API on August 2, 2026, the EU AI Act Article 50 enforcement date.
- Customers: Run a free scan at trooth.co.
- Developers: Read the Trooth Trust Protocol specification and the API reference.
- Security researchers: See our Vulnerability Disclosure Policy and /.well-known/security.txt.
- Procurement: Browse verified vendors in the Trooth Network.
Our compliance posture is documented at trooth.co/security. Government-verified credentials, self-attested conformance statements, subprocessor list, and customer documents available on request under NDA.
- General: hello@trooth.co
- Security: security@trooth.co
- Legal: legal@trooth.co
- Privacy: privacy@trooth.co
© 2025-2026 Trooth, LLC. Built, not bought.
