ThothOS is multi-tenant B2B software, so our #1 priority is tenant isolation — your company’s data is never visible to another company. Here is what we actually do today.
Because many companies share one platform, keeping each company’s data invisible to every other company is the control we care about most. Isolation is enforced at the data layer rather than only in the interface, and the boundary is exercised continuously by an automated cross-tenant test suite instead of being asserted in marketing copy.
tests/playwright/role-matrix/), and a cross-tenant isolation guard suite runs in CI. Counts and pass/fail are taken from the live suite — not a hand-typed marketing number.Beyond isolation, the data we hold is protected while it moves and while it sits at rest, and every privileged action is recorded so it can be reviewed after the fact. The specific safeguards we operate today are listed below.
We are working toward a formal attestation while keeping our current posture transparent, rather than staying silent until a certificate arrives to describe it.
𓂀[IN PROGRESS] SOC 2 readiness. SOC 2-aligned controls (the isolation, encryption, audit-logging, and access controls above) are implemented, and regressions against them are exercised by the check workflow in CI. That workflow is not yet a hard required status check on every merge, and the production build itself runs no guards — so treat CI coverage, not the build, as the enforcement point. A formal SOC 2 Type II audit has not yet commenced; a completed CAIQ/SIG is furnished to prospective customers on request.
Email security@thothos.net. We’ll acknowledge and respond promptly.
See our Privacy Policy, DPA, and Sub-processor list.