Skip to main content

Summary

When you use Triage Agent or Super Magic, Thread sends the relevant ticket context to Anthropic’s Claude models hosted on AWS Bedrock, in the United States. Requests travel over an encrypted AI gateway to AWS Bedrock, which runs the model inside AWS infrastructure. Under AWS’s published Bedrock terms, which Thread relies on: your inputs and outputs are not used to train any model, are not shared with the model provider (Anthropic), and are encrypted in transit and at rest. Anthropic has no access to your prompts, completions, or logs. Thread never trains or fine-tunes models on your data. Thread’s other AI features (Magic Recap, Magic Sentiment, Magic Title, auto-categorization, auto-prioritization, knowledge-base generation) continue to run on Azure OpenAI in the United States. See Magic AI Privacy & Security Overview for how that path works.

Which features this covers

These features are being enabled progressively. Until Claude on AWS Bedrock is enabled for a given workspace, Triage Agent and Super Magic run on Thread’s US-based Azure OpenAI deployment (encrypted, not used for training), as described in the Magic AI Privacy & Security Overview. Voice AI uses separate providers and is documented separately.

How your data flows

  1. A contact or technician interacts with Triage Agent or Super Magic on a ticket.
  2. Thread’s application assembles the necessary ticket context and sends the request over HTTPS/TLS to an encrypted AI gateway (Portkey), which handles secure routing.
  3. The gateway forwards the request to AWS Bedrock using AWS IAM authentication and TLS. Bedrock runs the Claude model and returns the response.
  4. Thread stores the AI conversation as part of the ticket record in Thread’s AWS environment (see Residency, retention, and encryption).
Processors on this path: Thread (application), AWS (Amazon Bedrock, which hosts and runs the model), and Portkey (the AI gateway). Anthropic provides the Claude models to AWS but has no access to your prompts, completions, or logs (see AWS Bedrock data protections), so it does not receive or process your data on this path. Each processor is bound by its data processing terms. AWS and Portkey appear on Thread’s published sub-processor list.

What data is processed

Only the context needed for the feature to do its job on the ticket at hand, which can include:
  • Ticket content: subject, conversation messages, internal notes, status, priority, timestamps.
  • Contact details on the ticket: name, email address, company name.
  • Where enabled by your admin: knowledge-base article content, learned contact memory, and results from connected tools (for example, device or documentation lookups).
  • Attachments: image attachments when image understanding is used, and text extracted from uploaded PDFs.
Every request is scoped to a single Thread workspace (identified internally by a unique workspace ID). Cross-tenant data is never included in a prompt. This context is sent to the model only to complete the task on that ticket; protection relies on per-workspace tenant isolation, your workspace access controls, and the AWS Bedrock terms below (no training, no sharing with the model provider).

AWS Bedrock data protections

Quoted from AWS’s published documentation:
  • Not used for training: “AWS and the third-party model providers will not use any inputs to or outputs from Amazon Bedrock to train … any third-party models.” (AWS Bedrock FAQ)
  • Not shared with the model provider: “Users’ inputs and model outputs are not shared with any model providers.” (AWS Bedrock FAQ)
  • Anthropic has no access: model providers “don’t have access to Amazon Bedrock logs or to customer prompts and completions.” (AWS Bedrock data protection documentation)
  • Encryption: customer content is encrypted in transit (TLS 1.2+) and at rest.
Thread accesses Claude exclusively through Bedrock. Anthropic acts as the model licensor to AWS on this path. It does not receive, store, or process your data.

Residency, retention, and encryption

Training on your data

Customer data is never used to train AI models.
  • AWS and Anthropic do not use Bedrock inputs or outputs to train models (see AWS Bedrock data protections).
  • Thread does not train or fine-tune any model on your data.

Tenant isolation

  • Application layer: every AI request is scoped to a single workspace. Prompts are assembled only from that workspace’s data, and audit records are keyed per workspace and per ticket.
  • Gateway layer: requests carry workspace-scoped metadata for attribution, and Thread operates dedicated gateway workspaces per environment, with production fully isolated from all non-production environments.
  • Inference layer: Bedrock processes each request in isolation within Thread’s AWS entitlement. No data is shared across AWS customers or with the model provider.

Human oversight and audit trail

  • Every Triage Agent and Super Magic action is recorded on the ticket, timestamped and attributable.
  • Write actions require human confirmation: when Super Magic proposes a change (create or update ticket, add note, log time, schedule, merge), the technician confirms in-product before it executes.
  • Admins control which write tools are available, to whom (including member-level allowlists), and per-tool on/off toggles. Integration tools are off by default.
  • A technician can take over any thread at any time, which deactivates the agent for that thread.
  • Triage Agent is bounded by per-customer, per-board, per-source activations and intent-level controls.

Customer controls

  • Admins can enable or disable Triage Agent and Super Magic per workspace at any time, without affecting other Thread features.
  • Knowledge-base generation and contact-memory learning can be disabled per workspace.
  • Access to AI features follows your existing workspace roles and permissions.

Compliance posture

  • Thread: SOC 2 Type II audit in progress (engagement started January 31, 2026). A bridge letter is available under NDA. Continuous control monitoring is available at Thread’s Trust Center.
  • AWS (Amazon Bedrock and application infrastructure): SOC 2 Type II, ISO 27001, HIPAA-eligible, GDPR-compliant.
  • Microsoft Azure (Thread’s other AI features): SOC 2 Type II, ISO 27001, ISO 27018, GDPR-compliant.
  • GDPR: Thread acts as a data processor for customer data. Data processing terms are available on request.

FAQ

No. Claude runs inside AWS Bedrock. Per AWS’s published documentation, model providers do not have access to Bedrock customer prompts, completions, or logs.
No. Not by AWS, not by Anthropic, not by Thread.
In the United States. Application data lives in AWS US East (N. Virginia), and Claude inference runs on Bedrock’s US-region capacity.
The ticket context described above: ticket content, the ticket’s contact details, and admin-enabled context like knowledge-base articles. Nothing outside your workspace.
Yes. Every AI action is recorded on the ticket in your workspace, with the full conversation visible to your team.
Yes. Both features can be disabled per workspace at any time, and Triage Agent can additionally be scoped per customer, board, and source.
Tickets continue to route to your technicians as normal, so an AI outage never blocks your support workflow.
The Type II audit is in progress (started January 31, 2026). A bridge letter is available now under NDA, and the final report will be shared when issued.