Effective March 1, 2026 · Updated April 21, 2026
Legal & Policy Center
All Trocola Inc. policies, terms, and procedures in one place. Use the search to find anything instantly.
Showing 16 of 16 policies
Policy 01 of 16
Terms of Service
1. Agreement to Terms
These Terms of Service ("Terms") constitute a legally binding agreement between you and Trocola Inc. ("Trocola Inc.," "we," "us," or "our"), governing your access to and use of the trocolainc.com website and all related services, certifications, assessments, events, and educational programs (collectively, the "Services").
By accessing or using any Trocola Inc. service, clicking "I Agree," completing enrollment, or attending a Trocola Inc. event, you agree to be bound by these Terms. If you do not agree, do not use our Services.
Important Notice
These Terms include a limitation of liability clause (Section 7) and a dispute resolution provision (Section 9). Please read them carefully. Trocola Inc. services are educational and advisory in nature and do not constitute legal advice.
2. Description of Services
Trocola Inc. provides the following services subject to these Terms:
- CSAP Certification Program (Series 1): Live instructor-led certification training for AI governance practitioners. Six sessions, 18 hours total, with exam and credential issuance.
- AI Governance Assessments: Structured organizational assessments including the 24-question AI Risk Assessment and full CT Framework evaluation.
- Consulting Engagements: Shadow AI Audits, Phase 1 Readiness Assessments, and full CT Framework certifications delivered by Trocola Inc. or certified consultants.
- Divisional Partner Program: Licensing agreements allowing qualified firms to source and deliver Trocola-branded services subject to a separate Divisional Partner Agreement.
- AI Safety Summit & Events: Live educational events including the annual AI Safety Summit.
- Digital Resources: Workbooks, SOP libraries, research reports, and tools provided to certified participants.
- IDEN Registry: AI agent identity and trust scoring platform (currently in development, access subject to separate terms upon launch).
2.8 IDEN Platform and Evidence Upload System
Clients engaged in certification or consulting workstreams upload compliance evidence to the IDEN platform. Evidence may include AI system inventories, policies, procedures, vendor agreements, training records, bias testing results, incident logs, and related governance documentation. The following terms apply to the evidence upload system:
- Access: Evidence uploads are accessible to Trocola Inc. auditors assigned to your engagement, the CSAP-certified practitioner or Divisional Partner delivering the engagement (where applicable), and authorized members of your organization. Evidence is not shared with other clients, other practitioners, or the general public.
- Confidentiality: All evidence submissions are treated as confidential business information of the uploading organization. Trocola Inc. does not disclose individual evidence content publicly, even when a certification status is posted to the public IDEN registry.
- Retention: Evidence uploads are retained per the Data Retention schedule in the Privacy Policy (Section 4). You may request deletion of non-public evidence records subject to the Data Deletion Policy.
- Security: Evidence is stored with encryption in transit and at rest, role-based access controls, and audit logging. Access events are recorded and available to the uploading organization upon request.
- Client Responsibility: Do not upload personal data of data subjects (customer PII, employee PHI, SSNs) as evidence. If evidence content would normally include such data, redact or summarize it before upload. Trocola Inc. does not need the underlying data to verify the control; the control documentation is sufficient.
3. Enrollment, Accounts, and Payment
3.1 Eligibility
You must be 18 years of age or older and have the legal capacity to enter into a binding agreement to enroll in any Trocola Inc. program. By enrolling, you represent that all information you provide is accurate and complete.
3.2 Account Registration
Certain services require account creation. You are responsible for maintaining the security of your account credentials and for all activity under your account. Notify us immediately at info@trocolainc.com if you suspect unauthorized access.
3.3 Email Matching Requirement
Critical: Email Address Policy
You must register on the learning platform using the same email address you used at checkout. If the emails do not match, access will be denied and Trocola Inc. is not responsible for missed sessions. To update your email before class begins, contact info@trocolainc.com at least 48 hours prior to session start.
3.4 Payment Terms
All fees are due at the time of enrollment unless a written payment plan has been agreed upon. Prices are listed in USD. Trocola Inc. reserves the right to change pricing at any time; however, enrolled participants are locked at the price paid at enrollment. Founding-rate pricing ($499 CSAP) is limited to the first 200 certified consultants and may be withdrawn without notice once the limit is reached.
3.5 Cohort Selection
Enrollment is cohort-specific. Your spot is reserved for the cohort selected at checkout. Cohort transfers are subject to availability and must be requested at least 7 days before your selected cohort begins.
4. Refund and Cancellation Policy
| Timing of Request | Refund Available | Conditions |
|---|---|---|
| More than 14 days before cohort start | Full refund | Written request to info@trocolainc.com required |
| 7 to 14 days before cohort start | 50% refund or full credit | Credit valid 12 months toward any Trocola Inc. program |
| Less than 7 days before cohort start | Credit only (no cash refund) | Credit valid 12 months |
| After first session attended | No refund or credit | Digital workbook and recorded sessions remain accessible |
| Missed session (no cancellation) | No refund | Recordings provided per enrollment policy |
Hardship Policy
Trocola Inc. recognizes that emergencies happen. If you experience a documented medical emergency, death in the immediate family, or involuntary job loss, contact us within 30 days of the event at info@trocolainc.com. We will review on a case-by-case basis and may offer extended credit or partial accommodation at our discretion.
4.1 Trocola-Initiated Cancellations
If Trocola Inc. cancels a cohort for any reason, enrolled participants will receive a full refund or the option to transfer to the next available cohort. Trocola Inc. is not responsible for any additional costs (travel, accommodations, lost wages) incurred by participants in connection with a cancellation.
5. Acceptable Use and Conduct
By using Trocola Inc. services, you agree not to:
- Share, resell, or sublicense Trocola Inc. course materials, workbooks, SOPs, or proprietary frameworks without written authorization
- Record, screenshot, or reproduce live session content without written permission
- Misrepresent your CSAP certification status, credential number, or scope of authorization
- Deliver AI governance services claiming Trocola Inc. affiliation without a valid, active Divisional Partner Agreement
- Use Trocola Inc.'s name, logo, or "Trocola-certified" designation without current authorization
- Submit falsified evidence, fraudulent assessments, or misrepresent compliance status to obtain certification
- Harass, threaten, or discriminate against other participants, instructors, or Trocola Inc. staff
- Circumvent access controls, attempt to access restricted content, or reverse-engineer Trocola Inc. platforms
Violations may result in immediate suspension or termination of access, revocation of certification, and civil or criminal referral where applicable.
6. Intellectual Property
All Trocola Inc. content including the CT Framework, CSAP curriculum, workbooks, assessment tools, SOP library, audit methodologies, IDEN platform, and brand marks are the exclusive property of and protected by U.S. and international copyright, trademark, and trade secret law.
Upon enrollment and payment, Trocola Inc. grants you a limited, non-exclusive, non-transferable license to use course materials for your own professional development and, upon successful certification, to deliver services within the scope of your certification level. This license does not include the right to reproduce, distribute, create derivative works, or sublicense any Trocola Inc. content.
Certification Scope of Use
CSAP-certified practitioners may use the CSAP credential, badge, and associated methodologies to deliver Shadow AI Audits and related services. Use of Trocola Inc. marks and the "Trocola-stamped" designation requires execution of a current Divisional Partner Agreement and annual CEU compliance.
7. Disclaimer and Limitation of Liability
Not Legal Advice
Trocola Inc. services are educational and advisory in nature. Nothing provided by Trocola Inc. constitutes legal advice, creates an attorney-client relationship, or guarantees any specific legal outcome. Certification reduces risk but does not eliminate legal exposure. Always consult qualified legal counsel for matters specific to your organization.
Trocola Inc. services are provided "as is." To the fullest extent permitted by law, Trocola Inc. and its officers, employees, and contractors shall not be liable for any indirect, incidental, consequential, special, or punitive damages arising from your use of or inability to use Trocola Inc. services, even if advised of the possibility of such damages.
Trocola Inc.'s total liability to you for any claims arising from these Terms or your use of the Services shall not exceed the total amount you paid to Trocola Inc. in the 12 months preceding the claim.
8. Termination and Decertification
Trocola Inc. may suspend or terminate your access and revoke any certification for:
- Violation of these Terms or the Divisional Partner Agreement
- Fraudulent evidence submission or misrepresentation
- Failure to maintain required CEU credits for annual recertification
- Two consecutive missed quarterly evidence uploads (certification suspension)
- Conduct deemed harmful to the Trocola Inc. brand, certification integrity, or the AI governance profession
Decertification is a matter of public record. Revoked certifications are noted in the IDEN registry with the reason for revocation. Five-year bans apply in cases of documented fraud or intentional misrepresentation.
8.1 Governing Law
These Terms are governed by the laws of the State of Delaware, without regard to conflict of law principles. Disputes shall be resolved in the state or federal courts located in Delaware. You waive any objection to venue in such courts.
Policy 02 of 16
Privacy Policy
Our Commitment
We collect only what we need. We never sell your personal information. When we use your data for research or case studies, we anonymize it completely: your company name and identifying details are never disclosed publicly.
1. Information We Collect
1.1 Information You Provide
- Account & enrollment: Name, email, company, job title, phone number
- AI Risk Assessment: All answers, overall and pillar scores, compliance gaps, department selections, risk classifications, timestamp
- Consultation requests: Name, email, phone, company information, topics of inquiry
- Event registration: Name, email, company, job title, accessibility or dietary needs where applicable
- Payment: Billing name, address, and transaction details (processed by third-party payment processors; Trocola Inc. does not store card numbers)
- Communications: Content of emails, support requests, and feedback submitted to Trocola Inc.
1.2 Automatically Collected Data
- Usage data: pages viewed, features used, time spent, navigation paths
- Device and browser information, IP address (used for general geo-location at city/state level only)
- Session data via cookies (see Cookie Policy)
- Assessment activity: start/completion times, question progress
2. How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Providing and delivering services | Account, enrollment, assessment data | Contract performance |
| Scheduling consultations and events | Name, email, phone, company | Contract performance |
| Sending communications you requested | Email, preferences | Consent (withdrawable) |
| Anonymized industry research & reports | De-identified assessment data | Legitimate interests |
| Improving our services and assessment methodology | Usage data, assessment responses | Legitimate interests |
| Security, fraud prevention, legal compliance | Account, usage, communication data | Legal obligation / Legitimate interests |
2.6 AI and Large Language Model (LLM) Safeguards
We Do Not Put Your Data Into Third-Party AI Models
Trocola Inc. does not input identifiable client data, company names, compliance gap findings, assessment scores, or evidence submissions into any third-party LLM (ChatGPT, Claude, Gemini, Copilot, or any other consumer or enterprise AI tool). This is a hard rule, not a preference. Your data never trains someone else's model.
The following safeguards apply to AI use across Trocola Inc. operations:
- Assessment scoring is not AI-generated. Your AI Risk Assessment score is calculated by Trocola Inc.'s proprietary scoring algorithm using fixed weighted formulas. No third-party AI model sees your responses.
- Certification decisions involve human review. No organizational certification is issued solely on algorithmic output. A qualified Trocola Inc. auditor reviews evidence and makes the final determination.
- AI tools used internally are restricted to non-client data. Where Trocola Inc. uses approved LLMs for internal drafting or research, those sessions use only public information or fully anonymized data.
- Client evidence is never used to train AI models. Trocola Inc. does not sell, license, or provide identifiable client evidence to any AI vendor for training, fine-tuning, or evaluation purposes.
- Practitioners are bound by the same rule. CSAP-certified practitioners and Divisional Partners are prohibited under the Code of Conduct and AUP from inputting identifiable client data into any third-party AI system without an executed data processing agreement covering the specific AI vendor.
2.7 AICE Talent Identification Disclosure
Trocola Inc.'s Certified Practitioner methodology includes the Artificial Intelligence Competency Evaluation (AICE) framework. During certification engagements, CSAP-certified practitioners may identify employees within your organization who demonstrate strong AI literacy, governance instincts, or ability to serve in AI governance roles. This identification is delivered to you, the client, as part of the engagement report.
The following terms apply to AICE talent identification:
- AICE observations are shared with client leadership only. They are not shared publicly, with other clients, or with outside recruiters.
- Trocola Inc. does not use AICE observations to recruit employees away from certified clients. Practitioners are bound by the Code of Conduct's 12-month non-solicit provision.
- Employees identified through AICE are not added to any external talent pool, recruiter database, or marketing list without the employee's express written consent.
- Clients receive AICE observations as a governance staffing recommendation. What you do with the information inside your organization is your decision.
If you prefer your engagement to exclude AICE observations, notify your practitioner or email privacy@trocolainc.com before the engagement begins.
4. Data Retention
| Data Type | Retention Period |
|---|---|
| Assessment data | Account active + 3 years |
| Account information | Until deletion + 30 days |
| Communication records | 7 years (business records requirement) |
| Consent records | Until opt-out + 2 years |
| Anonymized research data | Indefinitely (cannot be linked back to you) |
| Legal/compliance records | 7 to 10 years |
| Payment/billing records | 7 years (tax and financial compliance) |
5. Your Privacy Rights (Including California Residents)
All users, regardless of location, have the following rights as a Trocola Inc. policy commitment:
- Access: Request a copy of all personal data we hold about you
- Correction: Update inaccurate or incomplete information
- Deletion: Request erasure (see Data Deletion Policy for process and exceptions)
- Portability: Receive your data in a structured, machine-readable format (CSV or JSON)
- Restriction: Request limits on how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw consent: At any time, for consent-based processing
- Non-retaliation: Trocola Inc. will not discriminate against you or deny services for exercising a privacy right
5.1 California Residents (CCPA/CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information Trocola Inc. has collected, the sources, the purpose, and the categories of third parties with whom it is shared
- Right to Delete: Request deletion of personal information Trocola Inc. has collected, subject to legal retention exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt Out of Sale or Sharing: Trocola Inc. does not currently sell or share personal information; if this changes, you may opt out at any time
- Right to Limit Use of Sensitive Personal Information: Request that Trocola Inc. limit its use of any sensitive personal information to what is necessary to provide services
- Right to Non-Retaliation: Trocola Inc. will not deny services, charge different prices, or provide a different level or quality of service because you exercised a CCPA right
- Right to Data Portability: Receive your personal information in a portable, readily usable format
Lookback Period: Trocola Inc. provides information about data collection and sharing for the 12 months preceding your request.
Authorized Agent: You may designate an authorized agent to make a request on your behalf. Trocola Inc. will verify the agent's authorization through a signed written permission from you and may additionally verify your identity directly. Email privacy@trocolainc.com to begin an authorized agent request.
Verification: Trocola Inc. will verify your identity before fulfilling a request. See the Data Deletion Policy (Section 2.3) for specific California verification standards.
Response Time: Trocola Inc. responds to CCPA requests within 45 calendar days. If more time is required, we will notify you of the extension (up to an additional 45 days) and the reason.
5.2 EU/EEA Residents (GDPR)
Residents of the European Union and European Economic Area have the rights listed above plus the right to lodge a complaint with their local data protection authority.
5.3 How to Exercise Your Rights
To exercise any privacy right, email privacy@trocolainc.com with subject line "Privacy Rights Request: [Request Type]." Include your full name, the email address associated with your account, and the specific right you want to exercise. We respond within 30 days for general requests and 45 days for CCPA requests.
6. Security
Trocola Inc. implements: TLS/SSL encryption in transit, encryption at rest for sensitive data, role-based access controls, multi-factor authentication for administrative access, and documented incident response procedures. In the event of a breach affecting your personal information, you will be notified within 72 hours of discovery as required by applicable law.
No system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
Policy 03 of 16
Shadow AI Policy
Trocola Inc.'s Core Position
"Shadow AI is not an emerging risk. It is a present-tense liability." Christopher Trocola, Founder and CEO, Trocola Inc. This policy governs Shadow AI as it applies to Trocola Inc.'s own operations, to client engagements, and as a template CSAP-certified practitioners may adapt for client implementation.
1. Definition of Shadow AI
Shadow AI refers to any artificial intelligence tool, platform, application, or AI-enabled feature used within an organization without formal documentation, approval, or registration in the organization's AI inventory (IDEN registry or equivalent).
Shadow AI includes but is not limited to:
- Consumer AI tools accessed via personal or company accounts (ChatGPT, Claude, Gemini, Copilot) without IT/compliance authorization
- AI features embedded in approved software that have not been separately identified and risk-classified (Category 3 Shadow AI)
- Browser extensions with AI capabilities (Grammarly AI, Otter.ai, AI summarizers)
- Department-purchased AI subscriptions not reported to IT or compliance
- API integrations built by individual employees or teams without governance review
- Third-party AI tools accessed via personal expense reports
Category 3 Shadow AI: The Hidden Risk
Category 3 Shadow AI is AI embedded inside software that was approved for a non-AI purpose. Example: A CRM approved in 2022 that has since added AI-driven lead scoring. The CRM is approved. The AI feature is not. Samsung's 2023 trade secret breach began exactly this way: engineers used a tool that was approved for its primary function without realizing its AI capability was uploading data to external servers.
2. Prohibited Shadow AI Uses
The following constitute Shadow AI violations under this policy:
- Inputting customer PII (Social Security Numbers, credit card numbers, bank accounts, health information) into any unapproved AI tool
- Inputting employee PHI, personnel records, or compensation data into unapproved AI
- Uploading trade secrets, proprietary source code, unreleased financial data, or competitive strategy documents to any AI tool without an executed Data Processing Agreement (DPA)
- Using AI to make or substantially influence employment decisions (hiring, termination, promotion) without bias testing and human review documentation
- Using AI to generate customer-facing legal, medical, or financial advice without human expert review and disclosure
- Using unapproved AI for any use case that processes data subject to HIPAA, FCRA, GDPR, CCPA, or COPPA without verified vendor compliance
- Installing AI browser extensions, plugins, or applications on company devices without IT authorization
- Purchasing AI subscriptions on personal or company credit cards without compliance pre-approval
3. Shadow AI Discovery Protocol
Trocola Inc.'s six-method discovery protocol (taught in CSAP Session 3) is the standard for identifying Shadow AI. Organizations implementing this policy should conduct discovery using all six methods:
4. Reporting Obligations
Any employee, contractor, or partner who discovers or suspects Shadow AI use must report it within 24 hours to the designated AI Governance contact. Trocola Inc. maintains an anonymous reporting mechanism: reports can be submitted without identifying the individual responsible.
For Trocola Inc. clients: reporting channels are established during Phase 1 engagement and documented in the Incident Response Playbook (CT-2026-04).
For Trocola Inc.'s own operations: report to compliance@trocolainc.com. Reports are treated confidentially and will not result in discipline for good-faith disclosure.
Non-Punitive Disclosure
Trocola Inc.'s approach to Shadow AI discovery is remediation-first, not punishment-first. Employees who self-report Shadow AI use in good faith before discovery will not face disciplinary action for the disclosure itself. The goal is visibility and governance, not punishment.
5. Consequences of Policy Violation
| Violation Type | First Occurrence | Repeat / Intentional |
|---|---|---|
| Unapproved tool with no sensitive data | Training + written warning | Access suspension + formal review |
| Unapproved tool with PII/PHI processed | Immediate access suspension + incident report + possible breach notification | Termination + legal referral |
| Trade secret or proprietary data exposed | Immediate suspension + legal review + customer notification if applicable | Termination + civil/criminal referral |
| Intentional policy circumvention or concealment | Termination | Civil and/or criminal prosecution |
Consequences for certified consultants: Shadow AI policy violations during client engagements may result in CSAP credential review, suspension, or revocation per the Trocola Inc. Certification Standards.
Policy 04 of 16
Data Collection Policy
1. Data We Collect and Why
| Data Category | Examples | Collection Method | Required? |
|---|---|---|---|
| Identity data | Name, email, phone, job title | Provided by you | Yes, for account creation |
| Company data | Company name, industry, size, role | Provided by you | Yes, for B2B services |
| Assessment data | Question responses, scores, gap analysis, risk classifications | Generated by you during assessment | Yes, for service delivery |
| Payment data | Billing name, address, last 4 digits (card data held by processor) | Payment processor at checkout | Yes, for paid services |
| Usage data | Pages visited, features used, session duration | Automatic: cookies and analytics | No: opt out available |
| Communication data | Email content, support tickets, survey responses | Provided by you | No: optional |
| Event data | Registration details, attendance records | Provided by you at registration | Yes, for event access |
2. Data Minimization Commitment
Trocola Inc. applies the principle of data minimization: we collect only the data necessary to deliver the specific service you requested. We do not collect sensitive personal categories (health, financial, racial or ethnic origin, political opinion, religious beliefs) except where voluntarily provided and directly relevant to a requested service.
AI assessment data, including your organization's compliance gaps and risk classifications, is treated as confidential business information. It is never disclosed individually. When used for research, it is fully anonymized to industry, company size, and score range only.
3. Third-Party Data Processors
Trocola Inc. uses the following categories of third-party processors, all governed by signed data processing agreements (DPAs):
- Hosting and infrastructure: Application and database hosting providers
- Email and marketing: Transactional and promotional email platforms
- Scheduling: Calendar and appointment booking services (e.g., Calendly)
- Payment processing: PCI-DSS compliant payment gateway (card data never touches Trocola Inc. servers)
- Analytics: Anonymized usage analytics (no personally identifiable behavioral tracking sold to third parties)
- Learning Management System: Platform hosting CSAP course content and recordings
Trocola Inc. does not use AI-based processing of your personal data for automated decision-making. Assessment scoring is algorithmic but does not constitute a legally significant automated decision: all certification decisions involve human review.
4. International Data Transfers
Trocola Inc. is headquartered in Delaware, United States. Data may be processed in the US or by service providers in other countries. For EU/EEA residents, international transfers rely on Standard Contractual Clauses (SCCs) approved by the European Commission. For all other jurisdictions, we apply equivalent protections contractually.
To request information about specific transfer mechanisms in place, contact privacy@trocolainc.com.
Policy 05 of 16
Data Deletion Policy
1. Your Right to Deletion
You have the right to request deletion of your personal data from Trocola Inc.'s systems. This right applies under CCPA (California residents), GDPR (EU/EEA residents), and as a general Trocola Inc. policy commitment for all users regardless of location.
Who Can Request Deletion
Any individual who has provided personal data to Trocola Inc., including website visitors, assessment users, enrolled students, event registrants, and consulting clients, may submit a deletion request. Account holders may also request deletion through their account settings.
2. How to Submit a Deletion Request
2.1 Submission Process
2.2 Authorized Agent Requests
You may designate an authorized agent to submit a deletion request on your behalf. The agent must provide written permission signed by you, and Trocola Inc. may contact you directly to verify the authorization.
2.3 California Verification Standards
For California residents submitting requests under the CCPA/CPRA, Trocola Inc. applies the following verification standards consistent with California Attorney General regulations:
- Reasonable degree of certainty: For standard access or deletion requests, Trocola Inc. matches at least two data points you provide (such as email, account creation date, or recent assessment completion) to records on file.
- Reasonably high degree of certainty: For deletion of sensitive data or data that if deleted in error would cause significant harm, Trocola Inc. matches at least three data points and may request a signed declaration under penalty of perjury confirming you are the consumer whose data is being requested.
- Password-protected accounts: Existing account holders may verify through their authenticated account session, plus re-authentication before sensitive actions.
- Non-account-holders: Individuals who have interacted with Trocola Inc. but do not hold an account (newsletter subscribers, event attendees, assessment takers without registration) will be verified through the email address used at the original interaction plus at least one additional data point.
- Minimum data required: Trocola Inc. does not require more information than necessary to verify identity. Information collected for verification is used only for verification and deleted afterward unless retention is legally required.
- When verification fails: If Trocola Inc. cannot verify identity with reasonable certainty, the request will be denied and you will be informed in writing within the response window. You may resubmit with additional verification data.
3. Deletion Timelines
| Action | Timeline |
|---|---|
| Identity verification | Within 5 business days of request |
| Deletion of active account data | Within 30 days of verification (45 days for CCPA) |
| Deletion from backup systems | Within 90 days (next backup cycle) |
| Notification to third-party processors | Within 30 days |
| Written confirmation to you | Within 35 days of verified request (50 days for CCPA) |
4. Exceptions to Deletion
Certain data cannot be deleted due to legal obligations:
- Financial and billing records required for tax compliance (7 years per IRS requirements)
- Communication records required for business legal defense (7 years)
- Certification records: Trocola Inc. is legally required to maintain records of issued and revoked certifications; however, personal identifiers can be minimized upon request
- Data subject to active litigation hold or regulatory investigation
- Consent withdrawal records (the record that you opted out must be retained to honor the opt-out)
Anonymized Data
Anonymized research data derived from your assessment responses cannot be individually deleted because it cannot be linked back to you. This data exists only in aggregate form (e.g., "68% of 500 assessed companies lack bias testing"). No individual or company can be identified from this data.
If your deletion request is fully or partially denied, you will receive a written explanation with the legal basis for retention and, where applicable, the option to request anonymization as an alternative to deletion.
Policy 06 of 16
Opt-In Procedures
1. Types of Consent Trocola Inc. Requests
| Consent Type | What It Covers | Method | Required? |
|---|---|---|---|
| Service Delivery Consent | Processing your data to deliver the service you enrolled in or requested | Enrollment / account creation constitutes consent | Required for service access |
| Marketing Communications | Trocola Inc. newsletters, industry reports, event invitations, promotional content | Explicit checkbox at registration (pre-unchecked) | Optional: you choose |
| Research Use | Using your assessment data in anonymized industry research and reports | Disclosed in Privacy Policy; opt-out available | Legitimate interest basis; opt-out available |
| Partner Communications | Having your event registration info shared with event co-hosts or sponsors | Disclosed at registration; opt-out checkbox provided | Optional: you choose |
| Analytics Cookies | Usage data collection via analytics cookies | Cookie consent banner on first visit | Optional: essential cookies only required |
| Case Study Participation | Your organization being referenced (even anonymously) in Trocola Inc. content | Separate written consent form | Fully optional; withdrawal available |
2. How Opt-In Works
Trocola Inc.'s Opt-In Standard
Trocola Inc. does not use pre-checked boxes for optional consent. Every consent checkbox for optional communications is unchecked by default. You actively choose to receive communications. We do not infer consent from inaction, account creation, or purchase.
For marketing communications specifically, Trocola Inc. uses confirmed opt-in (double opt-in) for email list enrollment:
3. Consent Records
Trocola Inc. maintains a consent record for every opt-in that captures: the date and time of consent, the specific version of the privacy notice presented, the channel through which consent was collected, and the scope of consent granted. You may request a copy of your consent record at any time by emailing privacy@trocolainc.com.
Consent records are retained for the duration of your consent plus 2 years following withdrawal, to demonstrate compliance with applicable law.
Policy 07 of 16
Opt-Out Procedures
1. How to Opt Out
Multiple Opt-Out Channels: Use Any One
You can opt out through any of the following channels. You do not need to use all of them: one request is sufficient and will be honored across all relevant channels.
| Channel | How to Use It | Processing Time |
|---|---|---|
| Email unsubscribe link | Click "Unsubscribe" at the bottom of any Trocola Inc. email | Immediate (within 1 business day) |
| Email request | Email info@trocolainc.com with subject "Opt-Out Request: [Your Name]" | Within 10 business days |
| Account settings | Log in → Account Settings → Communication Preferences | Immediate |
| Cookie preferences | Click "Cookie Settings" in the footer of any Trocola Inc. page | Immediate |
| Partner communications | Check the opt-out box at event registration, or email info@trocolainc.com after the fact | Within 10 business days |
| Do Not Track (browser) | Enable Do Not Track in your browser settings | Immediate on next session |
2. What You Can Opt Out Of
- All marketing and promotional email communications
- Trocola Inc. newsletter and industry research reports
- Event invitations (AI Safety Summit, webinars, workshops)
- Partner/sponsor communications connected to events you attended
- Analytics cookie tracking (non-essential cookies)
- Anonymized research use of your assessment data
- Case study inclusion (even anonymized)
You cannot opt out of:
- Transactional emails directly related to your account, enrollment, or purchase (receipts, access confirmations, policy change notices): these are required for service delivery
- Security notifications about your account
- Legal notices required by law
- Essential cookies required for site functionality (authentication, security)
3. Processing and Confirmation
Trocola Inc. processes all opt-out requests within 10 business days. You will receive an email confirmation of your opt-out within 2 business days of the request being processed. After opt-out:
- You will not receive the opted-out communication type from Trocola Inc.
- You may still receive one final confirmation email acknowledging the opt-out
- Your opt-out preference is recorded and honored even if you re-engage with Trocola Inc.'s website or services
- To re-subscribe to any communication type, you must actively opt back in
Re-Opt-In After Opt-Out
If you opt out of marketing communications and later wish to re-subscribe, you can do so at any time through your account settings or by submitting a new opt-in via the newsletter form on trocolainc.com. Opting back in does not retroactively restore missed communications.
If you believe you are receiving communications after a valid opt-out request, contact info@trocolainc.com immediately. Trocola Inc. takes opt-out failures seriously and will investigate within 48 hours.
4. California "Do Not Sell or Share" Opt-Out
Current Status: Trocola Inc. Does Not Sell or Share
Trocola Inc. does not currently sell personal information or share it for cross-context behavioral advertising. This opt-out mechanism exists so that California residents can preemptively opt out and so that we comply with the CCPA/CPRA requirement to provide a clear opt-out channel regardless of current practice.
4.1 How to Submit a "Do Not Sell or Share" Request
California residents may submit a Do Not Sell or Share request through any of the following channels:
- Footer link: Click "Do Not Sell or Share My Personal Information" in the site footer
- Email: Email privacy@trocolainc.com with subject "Do Not Sell or Share Request: [Your Name]"
- Global Privacy Control (GPC): Trocola Inc. honors browser-level GPC signals. If your browser sends a GPC signal, we treat it as a valid Do Not Sell or Share request for that session and associated account if logged in.
4.2 Authorized Agent
An authorized agent may submit a Do Not Sell or Share request on your behalf. The agent must provide written permission signed by you. Trocola Inc. may verify the agent's authorization directly with you.
4.3 Response and Duration
- No verification required for opt-out of sale/sharing: Under CCPA/CPRA, opt-out of sale or sharing does not require identity verification (unlike access or deletion requests).
- Processing time: Requests are honored within 15 business days of receipt.
- Duration: Your opt-out is honored for at least 12 months. After 12 months, Trocola Inc. may ask whether you wish to opt back in, but you are not required to respond. Your opt-out remains active unless you affirmatively opt back in.
- No retaliation: Trocola Inc. will not deny services, charge different prices, or provide a lower level of service because you exercised this right.
4.4 If Practices Change
If Trocola Inc. at any future time decides to sell or share personal information, we will update this policy, provide advance notice to affected users, and honor all existing Do Not Sell or Share requests without requiring resubmission.
Policy 08 of 16
Cookie Policy
1. Cookie Types We Use
| Cookie Type | Purpose | Duration | Can Opt Out? |
|---|---|---|---|
| Strictly Necessary | Authentication, security, session management, CSRF protection. Site cannot function without these. | Session or up to 1 year | No: required for site function |
| Functional / Preference | Remember your preferences (language, cookie settings, saved form data). | Up to 1 year | Yes |
| Analytics | Understand how users interact with the site. Used to improve content and navigation. Data is anonymized. | Up to 2 years | Yes: via cookie settings |
| Performance | Monitor site speed and error detection. Help us identify and fix technical issues quickly. | Session | Yes |
Trocola Inc. does not use advertising cookies, retargeting pixels, or third-party behavioral tracking cookies. We do not participate in ad networks or sell behavioral data to advertisers.
2. Managing Your Cookie Preferences
You have several options for controlling cookies:
- Cookie Settings Banner: When you first visit trocolainc.com, a cookie consent banner allows you to accept all, accept only essential, or customize by category.
- Cookie Settings Link: A "Cookie Settings" link in the website footer allows you to update your preferences at any time.
- Browser Settings: Most browsers allow you to view, delete, and block cookies. Note that blocking all cookies will prevent login and may break site functionality.
- Do Not Track: Trocola Inc. respects the browser-level Do Not Track (DNT) signal. When DNT is enabled, we disable non-essential tracking on your session.
3. Third-Party Cookies
Trocola Inc. uses a limited number of third-party services that may set their own cookies when you interact with embedded content or integrated tools on our site. These include:
- Calendly: Sets session cookies when you use the scheduling widget.
- Payment Processor: Sets session cookies during checkout. No payment data is processed on Trocola Inc. domains.
- Learning Management System: Sets authentication cookies when you access course content.
Trocola Inc. does not control these third-party cookies. You can opt out of third-party cookies through the providers' respective opt-out mechanisms or through your browser settings.
For a full list of cookies currently in use on trocolainc.com, contact privacy@trocolainc.com.
4. California Residents: Do Not Track and Global Privacy Control
4.1 Do Not Track (DNT)
Trocola Inc. honors the browser-level Do Not Track signal. When DNT is enabled in your browser:
- Non-essential analytics cookies are not set for your session
- Behavioral tracking is disabled
- Essential cookies required for site functionality (authentication, security) remain active because the site cannot function without them
4.2 Global Privacy Control (GPC)
Trocola Inc. honors the Global Privacy Control signal as a valid opt-out request under CCPA/CPRA. When your browser sends a GPC signal:
- Trocola Inc. treats it as a Do Not Sell or Share request for that browser session
- If you are logged into a Trocola Inc. account, the GPC signal is applied to your account and persists across sessions until you affirmatively opt back in
- Non-essential analytics cookies are disabled
- No verification is required for a GPC-triggered opt-out
4.3 How to Enable DNT or GPC
- Do Not Track: Enable in your browser settings under Privacy and Security. Note that many browsers have deprecated DNT in favor of GPC; both are honored by Trocola Inc.
- Global Privacy Control: Install a GPC-enabled browser (Brave, Firefox with GPC extension, or similar) or use a GPC browser extension.
4.4 No Retaliation
Trocola Inc. will not deny services, charge different prices, provide a different level of service, or otherwise retaliate against users who enable DNT or GPC signals. These are valid privacy preferences and we honor them.
Policy 09 of 16
AI Certification Standards Policy
Purpose of This Policy
This policy governs how Trocola Inc. issues, maintains, suspends, and revokes AI governance certifications. It establishes the standards that make a Trocola Inc. certification a documented audit trail. Certification is not a one-time event. It is an ongoing obligation.
1. Trust Score Tiers and Certification Thresholds
All certifications are anchored to the IDEN Trust Score system (0-300). Score thresholds determine both what a company is eligible to certify and the level of ongoing monitoring required.
| Score Range | Tier | Status | Monitoring Frequency |
|---|---|---|---|
| 0-50 | Negligible | Not eligible for certification | N/A |
| 51-100 | Minimal | Not eligible for certification | N/A |
| 101-150 | Controlled | Phase 1 Assessment eligible | Quarterly uploads required |
| 151-200 | Verified | CT Framework Certification eligible | Quarterly uploads + annual audit |
| 201-250 | Advanced | High Risk AI certification eligible | Monthly monitoring + quarterly uploads |
| 251-300 | Trusted System | Full certification including Unacceptable Risk use cases | Monthly monitoring + semi-annual external audit |
Gatekeeper Evidence: Non-Negotiable
Certain evidence items are Gatekeeper requirements: they must be present to advance to the next Trust Score threshold regardless of total point accumulation. Missing a single Gatekeeper item caps the score at the tier below. No exceptions. No waivers.
| Trust Score Gate | Required Gatekeeper Evidence |
|---|---|
| 101+ (Controlled) | Board Governance Charter, Vendor Questionnaire, AI System Inventory, Training Curriculum |
| 151+ (Verified): High Risk AI | Adverse Impact Testing, Human Review Process Documentation, Candidate Disclosure, Bias Audit Months 1-3 |
| 201+ (Advanced): Unacceptable Risk | External Audit Report, Tabletop Exercise Record, Auditor Qualification Documentation |
2. Certification Issuance
Certification is issued only after all of the following conditions are satisfied:
- All required evidence items uploaded to IDEN platform and reviewed by CT auditor within 48-hour review window
- All Gatekeeper evidence items accepted (no pending or rejected Gatekeeper items)
- Industry-specific deep-dive completed for regulated sectors (Healthcare, Financial Services, Hiring/Employment, Law Enforcement, Critical Infrastructure)
- Live technical testing passed: OAuth revocation, data deletion test, bias audit validation, incident response drill
- Policy alignment audit passed: Privacy policy matches architecture, TOS matches technical capability, customer disclosures match actual user flow
- Certification Committee Review completed with unanimous CERTIFY decision (or CERTIFY WITH CONDITIONS with documented remediation plan)
- Trust Score at or above the threshold for the requested certification tier
Badge issuance is valid for 12 months from the date of Certification Committee approval. The AI Safe Certified badge, Trust Score, and Certificate of Compliance are published on the IDEN public registry upon issuance.
3. Ongoing Monitoring Obligations
| Day Range | Activity | Consequence of Failure |
|---|---|---|
| Day 1-15 | Client uploads required quarterly evidence to IDEN platform | -10 Trust Score points per week delayed (max -50) |
| Day 16-30 | CT auditor reviews evidence; flags deficiencies within 48 hours | N/A (auditor obligation) |
| Day 31-45 | Client addresses deficiencies; Trust Score updated | Unresolved deficiencies result in score reduction |
| Day 46-60 | Quarterly compliance report issued to client and board | Escalation to board if Trust Score drops >30 points |
4. Recertification Triggers
The following events require immediate recertification regardless of where the organization is in the quarterly monitoring cycle.
5. Suspension and Decertification
Decertification Is Public
Decertification is reflected on the IDEN public registry with the reason. Customers, competitors, regulators, insurers, and acquirers can see it. This is intentional. Decertification without consequence is not accountability.
| Trigger | Action | Reinstatement Path |
|---|---|---|
| One missed quarterly upload | -10 pts/week; warning issued | Upload and remediate within 45 days |
| Two consecutive missed quarters | Certification suspended; badge marked "Under Review" | Full recertification from scratch |
| Fabricated or falsified evidence | Immediate decertification; 5-year ban | Reapplication after 5 years with enhanced monitoring |
| Major incident with improper response | Immediate suspension pending investigation | Full recertification after confirmed remediation |
| Terms of Service or Partner Agreement violation | Suspension pending Trocola Inc. review | Case-by-case determination |
| Misrepresentation of certification scope | Immediate decertification | Reapplication after 2 years with written remediation plan |
Policy 10 of 16
Consultant & Partner Code of Conduct
1. Scope and Binding Effect
This Code of Conduct applies to all CSAP-certified practitioners and Divisional Partners from the date of certification or partner agreement execution. It supplements, and does not replace, the Terms of Service and any Divisional Partner Agreement.
By accepting CSAP certification or executing a Divisional Partner Agreement, you agree to this Code as a condition of maintaining your credential and authorization to deliver Trocola-branded services.
2. Professional Standards
- Deliver all Trocola-stamped audits and assessments in strict accordance with the CT Framework methodology as taught in CSAP and updated in quarterly research reports
- Maintain current CEU credits as required for annual CSAP recertification
- Disclose to clients in writing that you are an independent CSAP-certified consultant and not a Trocola Inc. employee
- Use only approved Trocola Inc. templates, SOPs, and documentation standards for engagements billed as Trocola-stamped
- Refer clients to Trocola Inc. for services outside your authorized scope
- Maintain professional liability (E&O) insurance of at least $1,000,000 per occurrence while delivering Trocola-branded services
- Report suspected certification fraud, Shadow AI misrepresentation, or evidence fabrication to Trocola Inc. within 48 hours of discovery
- Represent yourself as a Trocola Inc. employee, officer, or agent without written authorization
- Guarantee specific legal outcomes, insurance savings amounts, or Trust Scores to prospective clients
- Deliver AI governance certifications (the Trocola Inc. AI Safe Certified badge) without an active Divisional Partner Agreement
- Undercut the Redline pricing floor established in your Divisional Partner Agreement ($4,750 Phase 1, $35,000 full engagement)
- Share, sublicense, or resell Trocola Inc. proprietary frameworks, SOPs, or tools outside the scope of your licensing agreement
- Solicit Trocola Inc. clients for competing services during an active engagement or for 12 months following engagement completion
- Make public statements about pending or past legal matters involving Trocola Inc. clients without written client and Trocola Inc. approval
3. Client Relationship Standards
- Conflict of Interest: Disclose in writing any existing or prior relationship with a prospective client's vendors, competitors, or regulatory counterparties before engagement
- Confidentiality: Client assessment data, gap findings, and compliance gaps are confidential business information. Do not discuss, publish, or reference identifiable client information without written consent.
- Accuracy: Report findings accurately. Do not adjust scoring to satisfy client preferences or secure ongoing business.
- Scope: Do not expand the scope of an engagement beyond what is documented in the signed Statement of Work without written client approval and notification to Trocola Inc.
- Competence: Do not accept engagements requiring industry-specific expertise (Healthcare HIPAA, Financial Services FCRA) without the requisite knowledge.
4. Enforcement and Appeals
Violations of this Code are reviewed by Trocola Inc.'s Certification Standards Committee. The Committee may impose written warning, mandatory retraining, temporary suspension, permanent revocation of CSAP credential, and/or removal from the IDEN certified consultant registry.
To appeal a disciplinary action, submit a written appeal to standards@trocolainc.com within 30 days of the decision. Appeals are reviewed by a panel that does not include the original decision-maker. Appeal decisions are final.
Policy 11 of 16
AI Disclosure Policy
Trocola Inc. Practices What It Certifies
Trocola Inc.'s CT Framework requires client organizations to disclose AI use to their customers and stakeholders. This policy documents how Trocola Inc. itself complies with the same disclosure standards it enforces.
1. Trocola Inc.'s Internal AI Use Disclosure
| Use Case | AI System(s) Used | Data Involved | Human Review |
|---|---|---|---|
| Research and content drafting | Approved LLMs (updated in IDEN registry quarterly) | Public data, anonymized frameworks: no client PII | All published content reviewed by Trocola Inc. staff before release |
| Assessment scoring algorithm | Proprietary scoring logic (not third-party LLM) | Your anonymized assessment responses | Certification decisions always involve human auditor review |
| Internal communications and drafting | Approved LLMs per Trocola Inc. AUP | Internal communications only: no client data input | All client-facing communications reviewed before sending |
| Platform development and testing | Approved coding assistance tools | Anonymized test data only | All code reviewed by engineering lead before deployment |
What We Never Do with AI
Trocola Inc. never inputs identifiable client assessment data, company names, compliance findings, or gap analysis results into any third-party AI system. Client data is processed only within Trocola Inc.'s own systems and with service providers under executed DPAs.
2. Consultant AI Disclosure Requirements
CSAP-certified practitioners delivering Trocola-branded engagements must disclose AI use to clients in accordance with the following standards (mirroring CT Framework C-010):
| Engagement Phase | Disclosure Required | Timing |
|---|---|---|
| Proposal / SOW | Disclose whether AI tools will be used in report drafting, document analysis, or evidence review. Name the tools or categories. | Before engagement start |
| Discovery / Interviews | Disclose if AI transcription or summarization tools are used during recorded interviews or workshops. | Before recording begins |
| Report Delivery | State in the report header whether AI was used in drafting and confirm that a qualified human auditor reviewed all findings. | In every delivered report |
| Evidence Review | Do not use AI to make or substitute for auditor judgment on evidence acceptance/rejection. | Throughout engagement |
Client data may not be input into any AI system not covered by an executed DPA between the consultant and the AI vendor, and a separate DPA or data handling agreement between the consultant and the client.
2.4 CSAP Practitioner AI Use During Client Engagements
This subsection sets the minimum disclosure and handling standard for any CSAP-certified practitioner or Divisional Partner using AI tools during a client engagement. These requirements mirror what practitioners are taught during CSAP certification training and apply regardless of whether the engagement is Trocola-stamped.
Mandatory Practitioner Disclosures to Clients
- Disclose at proposal stage which AI tools, if any, the practitioner plans to use during the engagement and for what purpose (drafting, research, summarization, document analysis, transcription)
- Disclose whether client data will be input to any AI tool, and if so, under what DPA and confidentiality safeguards
- Obtain written client acknowledgment of AI tool use before any client data is shared with an AI system
- Document the AI disclosure as part of the engagement file, retained for the professional liability period
- Include an AI-Use Statement in the final report header disclosing whether AI was used in drafting and confirming human auditor review of all findings
Prohibited Practitioner AI Uses
- Inputting client PII, PHI, financial account data, or authentication credentials into any AI system
- Inputting client trade secrets, unreleased business data, or confidential compliance findings into consumer AI tools
- Using AI output as a direct substitute for practitioner judgment on evidence acceptance or certification recommendations
- Using AI to generate legal conclusions, regulatory opinions, or compliance attestations delivered to clients
- Retaining client data in AI vendor accounts after engagement completion
- Using consumer AI tools (free ChatGPT, free Claude, free Gemini) for any task involving identifiable client data
Required Practitioner Controls
- Approved tools only: Practitioners may use only AI tools from the Trocola Inc. approved inventory or with written pre-approval from Trocola Inc. for a specific engagement
- DPA in place: Any AI tool used with client data must have a DPA in place between the practitioner and the AI vendor, plus client authorization
- Opt-out of training: Practitioners must use AI vendor settings that prevent use of inputs for model training (enterprise mode, API mode with zero retention, or equivalent)
- Human review mandatory: Every client deliverable must be reviewed by the practitioner before delivery. AI-generated content is a draft, not a final product.
- Audit trail: Practitioners should be able to identify which portions of a deliverable were AI-assisted if requested by the client or in an audit
Violations of these requirements are Code of Conduct violations subject to credential review, suspension, or revocation per the Consultant and Partner Code of Conduct (Policy 10).
3. Platform and Assessment AI Disclosure
When you complete the Trocola Inc. AI Risk Assessment or use the IDEN platform:
- Your responses are processed by Trocola Inc.'s proprietary scoring algorithm, not a third-party AI model
- The algorithm calculates pillar scores and Trust Score using fixed weighted formulas; it does not learn from or retain your specific responses for model training
- Recommendations generated in your assessment report are template-based outputs tied to your specific gap findings, not AI-generated text
- No third-party AI has access to your assessment data
For questions about AI use in any specific Trocola Inc. tool or process, contact compliance@trocolainc.com.
Policy 12 of 16
Acceptable Use Policy for AI Systems
This Is Gatekeeper Evidence C-008
Under the CT Framework, an Acceptable Use Policy is Gatekeeper evidence worth 13 points: required to reach Trust Score 101. Trocola Inc. publishes its own AUP to demonstrate compliance with the same standard it certifies. This document also serves as a model AUP that CSAP-certified practitioners may adapt for client implementation.
1. Scope
This policy applies to: all Trocola Inc. employees and contractors; all CSAP-certified practitioners when acting under Trocola Inc. authorization; all Divisional Partners delivering Trocola-branded services; and all users accessing Trocola Inc. platforms and tools.
This policy covers: all AI systems provided by Trocola Inc., all third-party AI systems used for Trocola Inc. business, and all AI-generated content, decisions, recommendations, or data used in connection with Trocola Inc. services.
2. Approved AI Systems
Trocola Inc. maintains a current AI System Inventory registered in the IDEN platform. Only systems listed in the approved inventory may be used for Trocola Inc. business purposes. The current approved inventory is available to Trocola Inc. employees and partners at the IDEN client portal. The inventory is updated quarterly.
Use of AI systems not listed in the approved inventory is prohibited unless prior written approval is obtained from the Trocola Inc. Compliance Officer before use. Approval requests: compliance@trocolainc.com.
3. Prohibited Data Inputs
The following data types must never be input into any AI system, approved or otherwise, without a specific documented exception approved by the Compliance Officer:
- Client Social Security Numbers, credit card numbers, bank account numbers, or other financial account identifiers
- Employee or client health records, medical diagnoses, genetic information, or any PHI under HIPAA
- Passwords, API keys, encryption keys, authentication tokens, or any system credentials
- Children's personal information (any person under 18; COPPA-protected data)
- Trocola Inc. trade secrets, proprietary assessment methodology details, client compliance gap findings, or unreleased framework content
- Client company names, personnel names, or any identifiable client data without an executed DPA covering the specific AI system
- Legal hold data, data subject to active litigation, or confidential attorney-client communications
Acceptable Inputs
Fully anonymized data · Public regulatory texts and guidance · De-identified industry research · Internal draft documents containing no client-identifiable information · Approved datasets documented in the IDEN inventory
4. Prohibited Use Cases
- Making final employment decisions (hiring, termination, promotion) using AI output without documented human review
- Using AI-generated content as the sole basis for legal, medical, or financial advice delivered to clients
- Generating content designed to deceive, manipulate, or misrepresent Trocola Inc.'s services, certifications, or methodology
- Using AI to fabricate, alter, or inflate evidence intended for certification submission
- Bypassing security controls or using AI to gain unauthorized access to systems, data, or accounts
- Using AI to generate communications that impersonate Trocola Inc. personnel, certified practitioners, or clients
- Using unapproved AI tools on devices or networks used for Trocola Inc. business without explicit prior authorization
5. Required Practices
- Verify before using: AI outputs are not authoritative. Verify factual claims, legal citations, and data points from AI-generated content before using in client-facing work
- Maintain human judgment: Do not outsource professional judgment to AI. You remain accountable for decisions even when AI informed them
- Report problems: If AI produces biased, harmful, or obviously wrong outputs, report immediately to compliance@trocolainc.com with the AI system used, the input, the problematic output, the timestamp, and any screenshots
- Annual acknowledgment: All covered persons must acknowledge this AUP annually. New covered persons must acknowledge within 30 days of becoming covered
6. Consequences for Violations
| Violation Category | Potential Consequences |
|---|---|
| Unintentional / First occurrence | Verbal or written warning + mandatory retraining |
| Repeated or negligent violation | Suspension of AI system access + disciplinary review |
| Violation resulting in client data exposure | Immediate suspension + incident response + notification obligations + potential termination |
| Intentional misuse or evidence fabrication | Immediate termination + CSAP revocation + possible civil or criminal referral |
Policy 13 of 16
AI Incident Response Policy
This Policy Has Teeth
An incident response policy that exists only on paper is evidence of negligence, not compliance. Under the CT Framework, a live Incident Response Drill (tabletop exercise) is required gatekeeper evidence for Trust Score 201+. Trocola Inc. conducts its own tabletop exercises semi-annually.
1. Incident Types and Severity Classification
| Incident Type | Severity | Initial Response SLA | Escalation |
|---|---|---|---|
| Bias detection in certified AI system | High | 24 hours | AI Governance Committee + Legal Counsel |
| Data breach or unauthorized disclosure | Critical | Immediate (within 2 hours) | CISO + Legal + Privacy Officer + affected parties |
| AI hallucination causing documented harm | High | 24 hours | Legal + affected party notification + regulatory review |
| Shadow AI discovery (internal) | Medium-High depending on data exposed | 24 hours | Compliance Officer + IT Security |
| Certification fraud or evidence fabrication | Critical | Immediate | Trocola Inc. Certification Standards Committee + Legal |
| Platform security incident (IDEN/website) | Critical | Immediate | CISO + affected users + regulatory authorities |
2. Response Procedures by Incident Type
2.1 Data Breach or Unauthorized Disclosure
2.2 Bias Detection in Certified System
- Immediate: Notify certified organization. Advise suspension of the affected AI system from production use pending investigation.
- Within 24 hours: Trocola Inc. Certification Standards Committee reviews severity. Determine whether certification suspension is required.
- Within 7 days: Organization must submit bias remediation plan. Trocola Inc. reviews and approves or rejects.
- Recertification: Affected system requires full bias audit re-run and auditor sign-off before reinstatement.
2.3 Certification Fraud or Evidence Fabrication
- Immediate: Certification suspended. IDEN registry updated to "Under Investigation." Access to IDEN platform revoked pending review.
- Within 48 hours: Trocola Inc. Certification Standards Committee convenes. Evidence preserved for potential legal proceedings.
- Decision: If fraud confirmed: immediate decertification, 5-year ban, public notation in IDEN registry, referral to legal counsel for civil and/or criminal action.
- Reporting: Suspected fraud can be reported confidentially to standards@trocolainc.com. Trocola Inc. protects the identity of good-faith reporters.
2.4 CSAP Practitioner-Reported Incidents
CSAP-certified practitioners and Divisional Partners carry an affirmative obligation to report certain incidents to Trocola Inc. within 48 hours of discovery. This obligation exists because practitioners are often the first to observe client-side governance failures during engagements, and Trocola Inc.'s certification integrity depends on prompt reporting.
Incidents Practitioners Must Report
- Suspected certification fraud or evidence fabrication by a client or prospective client
- Material governance failures that call into question a current or recent certification determination
- Client disclosure of Shadow AI involving PII, PHI, or material trade secret exposure that the client has not addressed
- Requests by clients to adjust scoring, alter findings, or suppress gap findings for commercial reasons
- Observed data breaches or unauthorized access events affecting client AI systems
- Unauthorized use of the Trocola Inc. name, logo, or certification designation by any party
- Conduct by another CSAP-certified practitioner or Divisional Partner that violates the Code of Conduct
How to Report
- Email: standards@trocolainc.com with subject line "Practitioner Incident Report: [Brief Description]"
- Timeline: Within 48 hours of discovery
- Content: Describe the incident factually, identify the parties involved where known, note the date and circumstances of discovery, and indicate whether the client has been notified (if applicable)
- Confidentiality: Reporter identity is protected. Good-faith reports are not actionable against the reporting practitioner even if the underlying allegation is not ultimately substantiated.
Trocola Inc. Response
- Trocola Inc. acknowledges receipt within 2 business days
- Critical matters (active fraud, active breach) are triaged immediately with legal counsel
- Standard matters are investigated within 30 days and the reporting practitioner receives a summary of outcome (not the full investigation file)
- Failure to report a known incident is itself a Code of Conduct violation and may result in credential suspension
3. Incident Response Contacts
| Role | Contact | Escalation SLA |
|---|---|---|
| AI Governance Committee | compliance@trocolainc.com | Immediate for Critical; 24 hrs for High |
| Privacy Officer | privacy@trocolainc.com | Within 4 hours for data breach |
| Certification Standards Committee | standards@trocolainc.com | Within 48 hours for certification issues |
| General Inquiries | info@trocolainc.com | 2 business days |
4. Tabletop Exercise Requirement
Trocola Inc. conducts a formal incident response tabletop exercise twice per year. The exercise simulates at minimum one data breach scenario and one Shadow AI discovery scenario. Results are documented and filed in the IDEN audit log as evidence of Trocola Inc.'s own compliance with the CT Framework standard it certifies.
CSAP-certified practitioners delivering CT Framework engagements must facilitate at minimum one tabletop exercise with each client during the certification engagement (required gatekeeper evidence for Trust Score 201+).
Policy 14 of 16
Audit Scope and Limitations Policy
Read This First
Every Trocola Inc. audit, assessment, and certification engagement has a defined scope. Trocola Inc.'s findings, conclusions, Trust Scores, and certifications apply only to what was examined within that scope, during the period of the engagement.
1. What Trocola Inc. Audits
Trocola Inc.'s audit and assessment services cover the following, limited to what is expressly disclosed and submitted by the client organization during the engagement:
- AI systems and agents registered in the IDEN platform and identified in the client's AI System Inventory at the time of engagement
- Policies, procedures, and controls submitted as evidence through the IDEN evidence upload system during the active engagement window
- Vendor relationships, data processing agreements, and third-party integrations disclosed by the client and documented in the scope of work
- Technical controls tested live during the engagement, limited to systems and environments to which client has granted Trocola Inc. access
- Organizational controls validated through documentation, interviews, and observation during the engagement period
- Policy-to-practice alignment for the specific systems, policies, and workflows reviewed during the engagement
- Bias testing conducted on data sets and model versions provided by the client during the engagement window
2. What Trocola Inc. Does Not Audit and Is Not Responsible For
Scope Is Defined by Disclosure
Trocola Inc. can only assess what is disclosed. Systems, agents, vendors, data flows, or business practices not identified by the client during the engagement are outside scope. Certification does not mean a company is compliant in all respects: it means the disclosed, registered systems met the standard as tested.
- AI systems, agents, or tools not registered in IDEN and not disclosed in the client's submitted AI System Inventory
- Shadow AI discovered after the engagement closes that was not identified during the active shadow AI discovery phase
- Vendor updates, model retraining, or AI system changes made after the certification date
- Business decisions, product launches, or operational changes made by the client after certification is issued
- Legal advice, regulatory filings, or regulatory interpretation. Trocola Inc. assessments describe compliance posture based on the CT Framework methodology; they do not constitute legal advice
- Third-party implementations, deployments, or advice delivered by CSAP-certified consultants or Divisional Partners outside of a direct Trocola Inc. engagement
- Client misrepresentation of their AI systems, data flows, or controls. Certification fraud reverts all liability to the client.
- Systems or data environments to which Trocola Inc. was not granted access and therefore could not test
- Post-engagement regulatory changes that alter the compliance status of previously certified systems
3. Independent Consultant and Partner Liability
CSAP-certified practitioners and Divisional Partners are independent professionals who have earned authorization to deliver Trocola-branded services. They are not employees, contractors, or agents of Trocola Inc.
- Independent Delivery: When a practitioner delivers a Shadow AI Audit, Phase 1 Assessment, or related service under their own Statement of Work, that engagement is between the practitioner and the client. Trocola Inc. is not a party to that agreement.
- Misrepresentation: Any misrepresentation of Trocola Inc.'s services, scope, methodology, pricing, outcomes, or certifications by a consultant or partner is the sole responsibility of that consultant or partner.
- Service Quality: Trocola Inc. certifies methodology and credentials, not the quality of any individual engagement delivery. Client disputes about quality must be addressed with the practitioner directly.
- Unauthorized Claims: If a consultant or partner claims to offer Trocola-issued certifications without the required Divisional Partner Agreement, those claims are unauthorized. Report to compliance@trocolainc.com.
- Recourse: Clients who believe a certified practitioner has violated the Code of Conduct may submit a written complaint to standards@trocolainc.com. Trocola Inc. will investigate credential violations but is not responsible for financial damages arising from independent practitioner conduct.
How to Verify an Authorized Practitioner
All active CSAP-certified practitioners are listed in the IDEN public registry at trocolainc.com/contact/. Verify your practitioner's credential number and current authorization status before engagement.
4. Point-in-Time Nature of Certification
All Trocola Inc. certifications and assessments are point-in-time evaluations. A certification reflects the compliance posture of the disclosed, registered AI systems as of the certification date. It does not represent a guarantee of future compliance.
The following do not retroactively invalidate a certification but do trigger recertification obligations:
- Deployment of new AI systems after the certification date
- Vendor model updates or retraining events
- Regulatory changes affecting certified systems
- Documented AI incidents occurring post-certification
5. Not Legal Advice
Trocola Inc. assessments, audit reports, Trust Scores, and certifications describe compliance posture based on the CT Framework methodology. They do not constitute legal advice, do not create an attorney-client relationship, and do not guarantee any specific outcome in litigation, regulatory enforcement, or insurance claims.
Certification reduces documented risk by creating a defensible audit trail. It does not eliminate risk. Trocola Inc. strongly recommends that all certified organizations retain qualified legal counsel for regulatory compliance obligations specific to their jurisdiction and industry.
6. Trocola Inc. Liability in Connection with Audit Services
Trocola Inc.'s aggregate liability for any claims arising from or related to an audit, assessment, or certification engagement is limited to the total fees paid by the client to Trocola Inc. for that specific engagement during the 12 months preceding the claim. Trocola Inc. is not liable for: regulatory fines or penalties assessed against a certified organization; losses arising from AI system failures that occurred after the certification date; losses attributable to client misrepresentation of systems or controls during the engagement; or claims arising from the independent conduct of CSAP-certified practitioners or Divisional Partners.
Policy 15 of 16
IDEN Registry and Agent Data Policy
Core Commitment
Company and organizational information collected through the IDEN registry is used solely to identify and track AI systems and agents registered within it. It is never sold, licensed, or monetized without your express written consent. You own your data. Trocola Inc. is the custodian.
1. What the IDEN Registry Is
The IDEN (Identity, Documentation, Evidence, Notation) Registry is Trocola Inc.'s platform for registering, tracking, and scoring AI systems and agents. Each registered system receives a unique identifier, a risk classification, a Trust Score, and an immutable audit trail of evidence submissions and compliance milestones.
The IDEN Registry serves three functions:
- Identity: Assigns a unique, persistent identifier to each registered AI system or agent
- Compliance Tracking: Stores evidence uploads, Trust Score history, certification status, and audit findings for registered systems
- Public Registry: Publishes a public-facing record for certified systems showing certification status, Trust Score tier, certification date, and any suspension or revocation events
2. Data Collected During Agent and System Registration
| Data Field | Purpose | Publicly Visible? |
|---|---|---|
| Organization name and jurisdiction | System ownership identification | Yes, for certified systems |
| AI system name and description | Registry identifier and public record | Yes, for certified systems |
| Vendor and technology stack | Risk classification and due diligence | No, internal use only |
| Department and use case | Risk classification | No, internal use only |
| Risk classification | Determines required controls | Trust Score tier only |
| Data types processed (PII, PHI, Financial, etc.) | Control requirement mapping and audit scope | No, internal use only |
| Trust Score (0 to 300) | Compliance maturity indicator | Tier visible for certified systems; raw score for Trocola Inc. and client only |
| Evidence submissions | Certification support and audit trail | No, confidential client records |
| Certification dates and history | Compliance lifecycle tracking | Status and dates visible for certified systems |
| Incident and decertification records | Registry integrity and public accountability | Yes, decertification is public record with reason stated |
3. Purpose Limitation: Identification Only
Company and organizational information collected through the IDEN registry is used exclusively for the following purposes:
- Identifying the owning organization of a registered AI system or agent
- Linking compliance evidence, audit findings, and Trust Score records to the correct registered system
- Publishing the public registry record for certified systems
- Enabling Trocola Inc. auditors and authorized CSAP practitioners to access the relevant records during an active engagement
- Responding to verified regulatory, legal, or law enforcement requests as required by law
- Generating anonymized industry research and benchmarking reports where individual organizations and systems cannot be identified
- Selling, licensing, renting, or otherwise transferring identifiable company or agent data to any third party for commercial purposes without express written consent
- Using registered agent data for advertising, marketing profiling, or behavioral targeting of any kind
- Sharing vendor, technology stack, or data-type details with competitors or insurers
- Training third-party AI models on identifiable client evidence submissions or compliance gap data
- Publishing raw Trust Scores, risk classifications, or evidence details without the explicit consent of the registered organization
4. Data Storage and Third-Party Infrastructure
Trocola Inc. stores IDEN registry data in secure, access-controlled infrastructure. As the platform scales, Trocola Inc. may partner with third-party infrastructure providers for data storage, replication, and integrity verification. This includes the possibility of blockchain-based storage for immutable audit trail records.
Blockchain and Distributed Storage Disclosure
Trocola Inc. may use blockchain infrastructure to store audit trail records, certification events, and Trust Score history. The purpose is immutability: once a certification is issued or revoked, the record cannot be altered or deleted.
- What is stored on blockchain: Cryptographic hashes of certification events (not raw evidence documents), Trust Score change records, and certification status timestamps.
- What is not stored on blockchain: Raw evidence documents, company names in plaintext, compliance gap findings, vendor details, or any data that could be publicly read from the ledger.
- Third-party storage providers: All third-party storage partners are governed by executed data processing agreements.
- Immutability of decertification records: Decertification and revocation events are intentionally permanent on the public registry.
Current Storage Partners
Trocola Inc. currently works with Starchive for blockchain audit trail infrastructure. To request the current complete list of storage providers, email privacy@trocolainc.com.
5. Data Is Never Sold Without Express Written Consent
Trocola Inc. does not sell, license, or transfer identifiable company or agent data to any third party for any commercial purpose. This is an absolute commitment.
The only circumstances under which Trocola Inc. would transfer identifiable data to a third party for any purpose other than service delivery are:
- Express Written Consent: You have provided a separate, specific, written authorization for a defined data transfer to a named recipient for a named purpose.
- Legal Obligation: Trocola Inc. is compelled by court order, regulatory mandate, or law enforcement request under applicable law.
- Business Transfer: In the event of a merger, acquisition, or asset sale, data may transfer to the acquiring entity with advance written notice.
No Implied Consent
Enrolling in Trocola Inc. certification, registering an AI system in IDEN, or completing an assessment does not constitute consent to data sale or commercial transfer. The only consent Trocola Inc. accepts for data transfers beyond service delivery is a written, signed document specifying the transferee, the data scope, and the purpose.
6. Misrepresentation of IDEN Registry Data
The IDEN registry is a public-facing record of AI system compliance. Trocola Inc. takes the integrity of that record seriously. The following constitute misrepresentation violations:
- Displaying a Trocola Inc. certification badge or Trust Score on a product, website, or marketing material when the associated system's certification has expired, been suspended, or been revoked
- Representing that a system is Trocola-certified when it has not completed the certification process
- Representing a Trust Score or certification status that differs from the current IDEN registry record
- Using the Trocola Inc. certification badge for a system other than the one for which it was issued
- Claiming Trocola Inc. partnership, certification, or endorsement without a current, active Divisional Partner Agreement or CSAP credential
To report suspected misrepresentation, contact compliance@trocolainc.com.
7. Your Rights Over Registered Data
- Access: Request a full export of all data associated with your registered systems
- Correction: Request correction of factual errors in your registration record
- Deletion of non-public data: Request deletion of internal records subject to the Data Deletion Policy
- Portability: Receive your IDEN registration data in a structured, machine-readable format (JSON or CSV)
- Withdrawal from public registry: Organizations that choose not to renew certification may request removal of their public listing after expiration
To exercise these rights, contact privacy@trocolainc.com with subject "IDEN Registry Rights Request."
Policy 16 of 16
Certification Terms & Scope of Authorization
Purpose of This Policy
This policy defines what each Trocola Inc. certification authorizes (and does not authorize), the difference between Trocola-delivered services and partner-delivered services, what "Trocola-certified" means vs. "Trocola-stamped" vs. "CSAP-certified", and division of responsibility between Trocola Inc., certified practitioners, and Divisional Partners.
1. Trocola Inc. Certification Levels
1.1 Shadow AI Assessment (Entry-Level)
What It Is:
- Structured 24-question risk assessment covering 8 compliance pillars
- Identifies Shadow AI exposure and governance gaps
- Generates compliance gap report and initial risk classification
- Typical completion time: 15 to 30 minutes
- Output: Gap analysis report, NOT certification
What It Authorizes:
- Organization receives a compliance gap report for internal use
- Report may be shared with legal counsel, insurers, or board
What It Does NOT Authorize:
- Public representation as "Trocola-certified"
- Use of Trocola Inc. certification badge or Trust Score
- Marketing as having completed Trocola Inc. certification
- Representation to customers, regulators, or in RFPs that governance framework is certified
Delivered By: Self-service online assessment (direct through trocolainc.com), CSAP-certified practitioners (as part of discovery engagement), Trocola Inc. staff (as part of consulting engagement scoping)
Cost: Self-service: Free (publicly available) | As part of practitioner engagement: Included in discovery engagement pricing
1.2 CT Framework Certification (Full Certification)
What It Is:
- Complete governance framework implementation across 7 deliverable categories
- AI inventory, approved lists, SOPs, training records, vendor due diligence, incident response, audit trail
- Trust Score assignment (0 to 300) based on evidence submitted
- Trocola Inc. Certification Committee review and approval
- Certification valid for 12 months from issuance date
What It Authorizes:
- Public representation as "Trocola-certified organization"
- Use of Trocola Inc. "AI Safe Certified" badge on website, marketing materials, and proposals
- Display of Trust Score tier (Controlled, Verified, Advanced, Trusted System) in public-facing materials
- Listing in IDEN public registry as certified organization
- Representation in RFPs that governance framework meets Trocola Inc. standard
What It Does NOT Authorize:
- Representation that organization is "compliant" with specific laws (HIPAA, CCPA, etc.) without separate legal review
- Representation that Trocola Inc. provides legal advice or guarantees legal outcomes
- Use of Trocola Inc. certification badge for AI systems not registered in IDEN inventory
- Representation as Trocola Inc. partner, affiliate, or employee without separate agreement
Cost: Trocola-delivered: $25,000 to $75,000 (12 to 18 week engagement) | Practitioner/Partner-delivered: Set by practitioner (Trocola Inc. does not control independent practitioner pricing)
1.3 Quarterly Monitoring Agreement (Ongoing Certification)
What It Is:
- Quarterly review of approved list, training records, SOPs, and incident log
- Trust Score updates based on new evidence and governance changes
- Written compliance memo deliverable each quarter
- Annual certification renewal upon continued compliance
- Keeps certification "active" and current
Consequences of Non-Compliance:
- Missed quarterly upload: -10 Trust Score points per week delayed (max -50)
- Two consecutive missed quarters: Certification suspended, badge marked "Under Review"
- Three consecutive missed quarters: Certification revoked, public registry updated
Cost: $8,000 to $24,000 per year (varies by organization size and complexity)
2. CSAP Practitioner Credentials
2.1 CSAP Certification (Individual Credential)
What It Authorizes Practitioner to Do:
- Conduct Shadow AI discovery engagements for clients
- Build AI inventories, approved lists, SOPs, and audit trail infrastructure
- Deliver Trocola Inc. Shadow AI Assessment (24-question tool) to clients
- Represent themselves as "CSAP-certified practitioner"
- Use CSAP credential badge on professional materials (LinkedIn, website, business cards)
What It Does NOT Authorize Practitioner to Do:
- Issue Trocola Inc. organizational certifications (Trust Scores, AI Safe Certified badge) without Divisional Partner Agreement
- Represent themselves as Trocola Inc. employees, officers, or agents
- Guarantee specific legal outcomes or provide legal advice
- Use Trocola Inc. name, logo, or "Trocola-certified" designation without current active credential
- Deliver services outside authorized scope (see UPL boundaries in training)
Practitioner's Obligations:
- Maintain E&O insurance ($1M minimum per occurrence)
- Complete annual CEU credits (requirements published separately)
- Comply with Code of Conduct and UPL boundaries
- Disclose to clients that they are independent practitioners, not Trocola Inc. employees
- Report suspected fraud, evidence fabrication, or material governance failures to Trocola Inc. within 48 hours
2.2 Divisional Partner Agreement (Organizational Authorization)
What It Authorizes Partner to Do:
- Deliver full CT Framework certifications to clients
- Issue Trocola Inc. Trust Scores and AI Safe Certified badges
- List clients in IDEN public registry as Trocola-certified
- Market services as "Trocola-certified Divisional Partner"
- Use Trocola Inc. Divisional Partner badge in marketing materials
What It Does NOT Authorize Partner to Do:
- Modify Trocola Inc. methodology, assessment tools, or certification criteria
- Issue certifications outside Trocola Inc. review and approval process
- Represent Trocola Inc. positions on legal, regulatory, or policy matters without authorization
- Undercut established pricing floors (defined in Partner Agreement)
- Sublicense Trocola Inc. methodology to third parties
3. What "Trocola-Certified" Means
Three Distinct Meanings
There are three distinct uses of "Trocola-certified" that mean different things. Understanding the difference is critical.
3.1 "Trocola-Certified Organization"
Meaning:
- Organization has completed full CT Framework certification
- Trocola Inc. Certification Committee reviewed and approved submitted documentation
- Organization has active Trust Score and AI Safe Certified badge
- Organization listed in IDEN public registry
- Certification is current (not expired, suspended, or revoked)
Verification: Check IDEN public registry at trocolainc.com/contact/
Does NOT Mean:
- Organization is legally compliant with all applicable laws
- Trocola Inc. guarantees organization's AI systems are safe or bias-free
- Organization is a Trocola Inc. partner, affiliate, or subsidiary
- All AI systems in organization are certified (only those registered in IDEN inventory)
3.2 "Trocola-Stamped Engagement"
Meaning:
- Engagement delivered by CSAP-certified practitioner or Divisional Partner
- Work product reviewed and approved by Trocola Inc. before stamp issuance
- Deliverables meet Trocola Inc. methodology standard
- Practitioner followed CT Framework as taught in CSAP training
Does NOT Mean:
- Work was performed by Trocola Inc. employees
- Trocola Inc. is liable for practitioner quality or conduct
- Documentation constitutes legal advice or guarantees legal outcomes
- All client AI systems are compliant (only those included in engagement scope)
3.3 "CSAP-Certified Practitioner"
Meaning:
- Individual completed Trocola Inc.'s CSAP certification training
- Practitioner passed certification requirements
- Credential is current (not expired, suspended, or revoked)
- Practitioner listed in IDEN public registry
Verification: Check practitioner credential number at trocolainc.com/contact/
Does NOT Mean:
- Practitioner is a Trocola Inc. employee or agent
- Practitioner is authorized to issue Trocola Inc. organizational certifications (requires Divisional Partner Agreement)
- Practitioner is an attorney or can provide legal advice
- Trocola Inc. is responsible for practitioner's independent work product
4. Trocola-Delivered vs. Partner-Delivered Services
4.1 Trocola-Delivered Services (Direct Engagement)
What This Means:
- Client contracts directly with Trocola Inc. /
- Work performed by Trocola Inc. employees or contractors under Trocola Inc. supervision
- Trocola Inc. is the contracting party and bears direct responsibility for deliverables
- Client invoiced by Trocola Inc. directly
Trocola Inc. Responsibilities:
- Quality of deliverables
- Timeliness of engagement completion
- Professional conduct of Trocola Inc. personnel
- Accuracy of Trust Score and certification determination
4.2 Partner-Delivered Services (Independent Practitioner or Divisional Partner)
What This Means:
- Client contracts with CSAP-certified practitioner or Divisional Partner firm
- Work performed by practitioner, not Trocola Inc. employees
- Practitioner is independent professional, not Trocola Inc. agent
- Client invoiced by practitioner/partner directly
Trocola Inc. Liability Limitations for Partner-Delivered Services
Trocola Inc. Does NOT:
- Control practitioner's day-to-day work or client relationships
- Guarantee practitioner quality or conduct
- Provide refunds for practitioner-delivered services (client contracts with practitioner, not Trocola Inc.)
- Bear professional liability for practitioner's independent work
Client Remedies for Practitioner Issues:
- Direct engagement disputes: Resolve with practitioner per engagement agreement
- Code of Conduct violations: File complaint with Trocola Inc. (standards@trocolainc.com)
- Quality concerns: Request Trocola Inc. review of deliverables before certification issuance
- Credential verification: Check current status at trocolainc.com/contact/ before engagement
5. Misrepresentation and Unauthorized Use
Prohibited Misrepresentations by Organizations:
- Displaying Trocola Inc. certification badge when certification has expired, been suspended, or revoked
- Claiming Trocola Inc. certification for AI systems not registered in IDEN inventory
- Representing Trust Score or certification status different from current IDEN registry record
- Using Trocola Inc. badge for marketing purposes after certification lapse
- Claiming Trocola Inc. partnership without executed Divisional Partner Agreement
Prohibited Misrepresentations by Practitioners:
- Representing as Trocola Inc. employee, officer, or agent without authorization
- Issuing Trocola Inc. organizational certifications without Divisional Partner Agreement
- Claiming active credential when expired, suspended, or revoked
- Using Trocola Inc. name or logo after credential termination
- Guaranteeing legal outcomes or representing Trocola Inc. services as legal advice
Consequences:
- Immediate certification/credential suspension
- Registry listing updated to "Revoked - Misrepresentation"
- 5-year ban on reapplication
- Trocola Inc. may pursue civil action for trademark infringement
Reporting Misrepresentation:
Email: standards@trocolainc.com
Subject: "Misrepresentation Report - [Organization/Practitioner Name]"
6. Certification Expiration and Renewal
12-Month Validity:
- All Trocola Inc. organizational certifications expire 12 months from issuance date
- Expiration date displayed on certification badge and IDEN registry listing
- 90-day renewal window opens before expiration date
Grace Period:
- 30-day grace period after expiration
- During grace period: certification marked "Renewal Pending" in registry
- Badge use permitted during grace period
- If not renewed by end of grace period: certification status changes to "Expired"
After Expiration:
- Badge use prohibited
- Registry listing shows "Expired [Date]"
- Organization must remove badge from all marketing materials within 10 business days
- Reinstatement requires full renewal process (not automatic)
7. Client Rights and Remedies
7.1 Verification Rights
Clients have the right to verify before engagement:
- For Organizations: Current certification status (check IDEN registry at trocolainc.com/contact/)
- For Practitioners: Current credential status, credential number, issuance date, expiration date
7.2 Complaint Process
For Trocola-Delivered Services:
- Email: info@trocolainc.com
- Subject: "Service Quality Concern - [Your Organization Name]"
- Trocola Inc. responds within 2 business days
For Practitioner-Delivered Services:
Remedies NOT Available
Trocola Inc. does not provide refunds for practitioner-delivered services (client contracted with practitioner, not Trocola Inc.). Trocola Inc. does not arbitrate pricing disputes or commercial disagreements. Trocola Inc. is not liable for practitioner's professional conduct in independent engagements.
7.3 Appeals Process
Certification denial, suspension, or revocation may be appealed to Trocola Inc. Certification Standards Committee within 30 days. Appeals reviewed by panel not including original decision-maker. Appeal decision is final.
8. Contact Information
| Purpose | Contact |
|---|---|
| General Inquiries | info@trocolainc.com |
| Certification Questions | standards@trocolainc.com |
| Practitioner Registry Verification | trocolainc.com/contact/ |
| Misrepresentation Reports | standards@trocolainc.com |
| Privacy & Data Requests | privacy@trocolainc.com |
Appendix A: Quick Reference Chart
| Certification Type | Who Can Deliver | What It Authorizes | What It Does NOT Authorize |
|---|---|---|---|
| Shadow AI Assessment | Self-service, CSAP practitioners, Trocola Inc. | Gap report for internal use | Public "Trocola-certified" claim, badge use |
| CT Framework Certification | Trocola Inc., CSAP practitioners, Divisional Partners | Badge use, Trust Score, registry listing, "Trocola-certified" claim | Legal compliance guarantee, badge for unregistered AI systems |
| Quarterly Monitoring | Trocola Inc. or partner who delivered certification | Continued badge use, annual renewal, updated Trust Score | Automatic renewal regardless of compliance |
| CSAP Credential | Trocola Inc. only | Deliver assessments, build governance frameworks, use CSAP badge | Issue organizational certifications (requires Partner Agreement) |
| Divisional Partner | Trocola Inc. only (application required) | Issue Trust Scores, AI Safe Certified badges, certify organizations | Modify Trocola Inc. methodology, undercut pricing floors |