Security & Trust Center

Security is core to everything we build

Thriven is built with security-first engineering practices. We protect your data with industry-standard encryption, access controls, and a transparent compliance roadmap designed for enterprise buyers.

๐Ÿ”’TLS 1.3 Encrypted๐Ÿ›ก๏ธAES-256 at Rest๐Ÿ‡ช๐Ÿ‡บGDPR Compliant๐Ÿ“‹SOC 2 In Progressโœ…OWASP Aligned
Infrastructure

Enterprise-grade infrastructure

We build on battle-tested cloud primitives with security and reliability built in โ€” not bolted on.

Vercel Edge Network

  • Global CDN with DDoS protection
  • Automatic HTTPS on all endpoints
  • Web Application Firewall (WAF)
  • Preview deployments isolated per branch

Neon Postgres

  • Serverless PostgreSQL with point-in-time recovery
  • Data encrypted at rest with AES-256
  • Automated daily backups with 30-day retention
  • Private networking โ€” no public DB exposure

Encryption & Transport

  • TLS 1.3 for all data in transit
  • HSTS enforced across all domains
  • AES-256 encryption for all stored data
  • No plaintext secrets in code or logs
Data Security

Your data stays yours

Strict data isolation, access controls, and retention policies ensure your data is protected at every layer.

Data Isolation

  • Logical tenant isolation per organization
  • Row-level security enforced at the database layer
  • API keys scoped per workspace โ€” no cross-tenant access
  • Strict server-side authorization on every request

Access Controls

  • Role-based access control (RBAC) for all resources
  • Principle of least privilege for all internal systems
  • Break-glass process for emergency access with full audit log
  • Regular access reviews for engineering team

Data Handling

  • No data sold or shared with third parties
  • Data retained only as long as needed for service delivery
  • 30-day deletion SLA upon cancellation or request
  • Export your data at any time in JSON or CSV
Application Security

Secure by design

Our development process includes security reviews, dependency scanning, and alignment with OWASP best practices.

Authentication

  • Modern auth provider with secure session management
  • MFA / TOTP support for all user accounts
  • Brute-force protection with rate limiting
  • Short-lived JWTs with secure refresh flow

Secure Development

  • OWASP Top 10 mitigations in all new code
  • Automated dependency vulnerability scanning (Dependabot)
  • Security review required for all auth and data-path changes
  • Secrets managed via environment variables โ€” never in source

Rate Limiting & Abuse

  • Per-IP and per-user rate limiting on all API endpoints
  • Input validation and parameterized queries everywhere
  • Content Security Policy (CSP) headers on all pages
  • Automatic bot detection and blocking at the edge
GDPR & Privacy

GDPR-compliant from day one

We are committed to protecting the privacy rights of your users and customers in accordance with EU data protection law.

Your Rights & Ours

  • Lawful basis documented for all processing activities
  • Data subject access requests fulfilled within 30 days
  • Right to erasure honored within 30 days of request
  • No transfers to non-adequate countries without safeguards

Data Processing Agreement

  • Standard DPA available to all customers
  • Email legal@thriven.ai to request your DPA
  • Custom DPA review available for enterprise customers
  • Updated to reflect SCCs under GDPR Chapter V

Sub-processors & Privacy

  • Full sub-processor list available on request
  • All sub-processors are GDPR-compliant
  • Privacy policy kept current at thriven.ai/privacy
  • Privacy-by-design applied to all product features

Read our full Privacy Policy or request a DPA by contacting legal@thriven.ai.

Request DPA โ†’
Bug Bounty

Responsible disclosure

We deeply appreciate security researchers who help us keep Thriven safe. Report vulnerabilities and we'll respond quickly and fairly.

How to Report

  • Email security@thriven.ai with full details
  • Include steps to reproduce and impact assessment
  • Attach screenshots or proof-of-concept if available
  • We acknowledge all reports within 48 hours

Our Commitments

  • 48-hour acknowledgement SLA for all reports
  • No legal action for good-faith security research
  • We'll keep you informed as we fix the issue
  • Hall of fame recognition for valid, responsible reports

Scope

  • thriven.nanocorp.app and all *.thriven.ai domains
  • Thriven web application and API
  • Authentication and authorization flaws
  • Injection, XSS, CSRF, and data-exposure bugs
Compliance Roadmap

Working toward industry certifications

We are actively building toward SOC 2 Type II and ISO 27001 to give enterprise customers the third-party assurance they need.

SOC 2 Type II

In Progress ยท Target 2026

We have completed an internal gap analysis and are implementing the required security controls across the Trust Service Criteria: Security, Availability, Confidentiality, and Privacy. We plan to begin the formal audit with an accredited CPA firm in late 2026.

โœ“Internal gap analysis complete
2Controls implementation underway
3Audit firm selected (Q3 2026)
4Formal audit period (Q4 2026)

ISO 27001

Planned ยท 2027

Following SOC 2 completion, we plan to pursue ISO 27001 certification to meet the requirements of EU-based enterprise customers. ISO 27001 aligns with our existing security management practices and will complement our SOC 2 controls framework.

1ISMS design (post-SOC 2)
2Risk assessment & treatment plan
3Internal audit
4Certification body audit (2027)
FAQ

Security FAQ

Common questions from enterprise buyers about how Thriven handles data, compliance, and security.

Where is my data stored?
Who has access to my data?
Can I get a DPA signed?
Do you offer SSO / SAML?
What happens to my data if I cancel?
Are you SOC 2 certified?

Have a security question not answered here? security@thriven.ai