Enterprise-grade infrastructure
We build on battle-tested cloud primitives with security and reliability built in โ not bolted on.
Vercel Edge Network
- Global CDN with DDoS protection
- Automatic HTTPS on all endpoints
- Web Application Firewall (WAF)
- Preview deployments isolated per branch
Neon Postgres
- Serverless PostgreSQL with point-in-time recovery
- Data encrypted at rest with AES-256
- Automated daily backups with 30-day retention
- Private networking โ no public DB exposure
Encryption & Transport
- TLS 1.3 for all data in transit
- HSTS enforced across all domains
- AES-256 encryption for all stored data
- No plaintext secrets in code or logs
Your data stays yours
Strict data isolation, access controls, and retention policies ensure your data is protected at every layer.
Data Isolation
- Logical tenant isolation per organization
- Row-level security enforced at the database layer
- API keys scoped per workspace โ no cross-tenant access
- Strict server-side authorization on every request
Access Controls
- Role-based access control (RBAC) for all resources
- Principle of least privilege for all internal systems
- Break-glass process for emergency access with full audit log
- Regular access reviews for engineering team
Data Handling
- No data sold or shared with third parties
- Data retained only as long as needed for service delivery
- 30-day deletion SLA upon cancellation or request
- Export your data at any time in JSON or CSV
Secure by design
Our development process includes security reviews, dependency scanning, and alignment with OWASP best practices.
Authentication
- Modern auth provider with secure session management
- MFA / TOTP support for all user accounts
- Brute-force protection with rate limiting
- Short-lived JWTs with secure refresh flow
Secure Development
- OWASP Top 10 mitigations in all new code
- Automated dependency vulnerability scanning (Dependabot)
- Security review required for all auth and data-path changes
- Secrets managed via environment variables โ never in source
Rate Limiting & Abuse
- Per-IP and per-user rate limiting on all API endpoints
- Input validation and parameterized queries everywhere
- Content Security Policy (CSP) headers on all pages
- Automatic bot detection and blocking at the edge
GDPR-compliant from day one
We are committed to protecting the privacy rights of your users and customers in accordance with EU data protection law.
Your Rights & Ours
- Lawful basis documented for all processing activities
- Data subject access requests fulfilled within 30 days
- Right to erasure honored within 30 days of request
- No transfers to non-adequate countries without safeguards
Data Processing Agreement
- Standard DPA available to all customers
- Email legal@thriven.ai to request your DPA
- Custom DPA review available for enterprise customers
- Updated to reflect SCCs under GDPR Chapter V
Sub-processors & Privacy
- Full sub-processor list available on request
- All sub-processors are GDPR-compliant
- Privacy policy kept current at thriven.ai/privacy
- Privacy-by-design applied to all product features
Read our full Privacy Policy or request a DPA by contacting legal@thriven.ai.
Request DPA โResponsible disclosure
We deeply appreciate security researchers who help us keep Thriven safe. Report vulnerabilities and we'll respond quickly and fairly.
How to Report
- Email security@thriven.ai with full details
- Include steps to reproduce and impact assessment
- Attach screenshots or proof-of-concept if available
- We acknowledge all reports within 48 hours
Our Commitments
- 48-hour acknowledgement SLA for all reports
- No legal action for good-faith security research
- We'll keep you informed as we fix the issue
- Hall of fame recognition for valid, responsible reports
Scope
- thriven.nanocorp.app and all *.thriven.ai domains
- Thriven web application and API
- Authentication and authorization flaws
- Injection, XSS, CSRF, and data-exposure bugs
Safe Harbor
Thriven will not pursue legal action against researchers who discover and report vulnerabilities in good faith, follow responsible disclosure practices, and avoid accessing, modifying, or deleting user data. We consider this research to be authorized under the Computer Fraud and Abuse Act (CFAA) and similar laws.
Working toward industry certifications
We are actively building toward SOC 2 Type II and ISO 27001 to give enterprise customers the third-party assurance they need.
SOC 2 Type II
In Progress ยท Target 2026We have completed an internal gap analysis and are implementing the required security controls across the Trust Service Criteria: Security, Availability, Confidentiality, and Privacy. We plan to begin the formal audit with an accredited CPA firm in late 2026.
ISO 27001
Planned ยท 2027Following SOC 2 completion, we plan to pursue ISO 27001 certification to meet the requirements of EU-based enterprise customers. ISO 27001 aligns with our existing security management practices and will complement our SOC 2 controls framework.
Security FAQ
Common questions from enterprise buyers about how Thriven handles data, compliance, and security.
Have a security question not answered here? security@thriven.ai