> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getthread.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Thread's SOC 2 and compliance status

> Thread's current SOC 2 Type II status, what you can share with a client today, and where to get live control monitoring, the security package, and signed agreements.

Partners ask this when a client's security review lands on their desk. This page gives you the
current status and the links you can send on. For anything beyond it — live control status, the
full security package, or a signed agreement — use the Trust Center.

<Card title="Thread Trust Center" icon="shield-check" href="https://app.vanta.com/getthread.com/trust/lp3d2rffaud4mely4xay7b">
  Live control monitoring, the current certification status, and the security documents available
  for request. This is the authoritative source — always link a client here rather than quoting a
  status from a doc that may have moved on.
</Card>

## Current status

| Framework         | Status                                                                                                                                            |
| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| **SOC 2 Type II** | Audit in progress. The report has **not** been issued yet. A bridge letter is available under NDA.                                                |
| **ISO 27001**     | Not certified. Thread runs an ISMS aligned to ISO 27001/27005 and NIST 800-30.                                                                    |
| **GDPR**          | Thread acts as a data processor for customer data. A DPA is available; data processing terms on request.                                          |
| **HIPAA**         | Thread is not HIPAA compliant and does not act as a Business Associate. Thread is an IT service desk and is not designed to receive or store PHI. |

<Warning>
  **Don't tell a client Thread "is SOC 2 certified" until the report is issued.** Until then the
  accurate phrasing is that the Type II audit is **in progress**, with a bridge letter available
  under NDA. Check the Trust Center for the current state before you put anything in writing — this
  page is reviewed periodically, the Trust Center is live.
</Warning>

## What you can send a client today

* **The Trust Center link** above — self-serve, always current, no NDA needed to view.
* **A bridge letter**, under NDA. Ask your Customer Success Manager.
* **The sub-processor list** — [Thread sub-processors](/security-billing/list-of-sub-processors).
* **The technical detail auditors actually ask for**: [data encryption](/security-billing/data-encryption), [Magic AI privacy & security](/security-billing/magic-ai-privacy-security), [Claude on AWS Bedrock](/security-billing/claude-on-aws-bedrock), and [IP addresses and domains to allowlist](/security-billing/what-if-my-organization-has-ip-restrictions).

## Infrastructure providers

Thread's own status is separate from its infrastructure's. Both matter to an auditor.

| Provider                       | What it runs                                 | Compliance                                     |
| ------------------------------ | -------------------------------------------- | ---------------------------------------------- |
| **AWS** (incl. Amazon Bedrock) | Application infrastructure and Claude models | SOC 2 Type II, ISO 27001, HIPAA-eligible, GDPR |
| **Microsoft Azure**            | Thread's other AI features                   | SOC 2 Type II, ISO 27001, ISO 27018, GDPR      |

## Answering a client security questionnaire

Two things help here, and they're different:

1. **Thread's posture** — this page plus the Trust Center. If a question isn't answered by either, ask your Customer Success Manager rather than inferring.
2. **Your own evidence** — the Magic Library has a compliance bench for assembling *your* documentation, including [SOC 2 evidence collection](/skill-library/compliance-and-audit/soc2-evidence-collection) and [security questionnaire / vendor DDQ](/skill-library/compliance-and-audit/security-questionnaire-vendor-ddq). Those help you answer for your own organisation; they don't stand in for Thread's attestations.


## Related topics

- [Security & Compliance Owner](/start-here/roles/security-compliance-owner.md)
- [Blackpoint SOC Response](/skill-library/vendor-runbooks/blackpoint-soc-response.md)
- [SOC Shift Handoff](/skill-library/security/soc-shift-handoff.md)
