Already documented
These topics are already covered — link to them directly:Data & encryption
What Thread stores, at-rest/in-transit encryption, and the data-residency FAQ (US-only hosting).
Magic AI privacy & security
Azure OpenAI isolation, no data retention, and no model training on customer data.
Sub-processors
The current sub-processor list and each provider’s purpose.
IP restrictions
Allowlisting guidance for restricted networks.
Data hosting & residency
Thread is a single-region, US-only platform: the application database and infrastructure run in AWS US-East, with Microsoft-side services on Azure US-East. There is no per-partner or per-client residency selection. This is already documented in the Data & encryption residency FAQ.🔶 Verify — Legal + Product: Confirm the customer-facing statement that Thread does not offer an EU/EEA data-residency option, and that cross-border transfers are governed by the EU SCCs in the DPA (see DPA & data transfers below).
AI & data handling
Covered in depth on Magic AI privacy & security: customer content is processed in memory only, never retained, and never used to train, retrain, or improve any model (Azure OpenAI and AWS Bedrock run on locked-down private instances).🔶 Verify — Product: Add an explicit “Knowledge ≠ Training” clarification — building a knowledge base from a partner’s data enriches answers with context at retrieval time and is isolated per workspace/end-customer; it does not train a model. Confirm wording before publishing.
Certifications & audits
🔶 Verify — Security + Legal (time-sensitive): All figures below are drafts from Slack and must be confirmed and kept current.
- SOC 2 Type II — reported as in progress (Security / Common Criteria, observation period started Jan 1 2026), under independent CPA review by Prescient Assurance; report not yet issued. Do not state or imply Thread “is SOC 2 certified” until the report is issued. Bridge/engagement letters are shared under NDA.
- Penetration testing — reported as an annual third-party pen test (Optiv, most recent May 2025), quarterly scans, with 30-day (critical) / 120-day (high) remediation targets. Executive summary under NDA.
- ISO 27001 — reported as not certified, but with an ISMS aligned to ISO 27001/27005 and NIST 800-30. Confirm the exact “aligned, not certified” phrasing.
Tenant isolation
🔶 Verify — Security/Engineering: Reported as multi-tenant isolation enforced server-side on every read/write, with a central authorization layer evaluating identity + tenant scope. Confirm the customer-safe description (no internal implementation detail).
Availability & resilience
🔶 Verify — Engineering: Draft figures below need confirmation and a source of truth.
- Reported uptime > 99.9% with hot failover; hosting RTO/RPO cited as 5 days / 10 days; annual DR testing.
- No customer-facing response-time SLA today — confirm this is the stance to publish.
- PSA-outage resilience: if a PSA or downstream system is down, Thread keeps receiving messages and queues outbound writes, posting them once service is restored (reported as no data loss). Confirm.
Data retention, export & deletion
🔶 Verify — Legal + Product: Reported as data deleted within 90 days of termination, with export available in CSV/JSON. Confirm the retention window, the deletion process, and the export mechanism.
Audit logging
🔶 Verify — Product: Reported that every AI/tool action is posted to the ticket and can optionally sync to the PSA, but there is no public audit-log API yet (customers pull from the PSA for a SIEM). Confirm current state before publishing.
Sub-processors & change notification
The maintained list lives on Sub-processors (currently dated August 2026 and appears current).🔶 Verify — Legal: Document the change-notification mechanism — reported as advance notice of any new/replacement sub-processor with a window to object before it takes effect (cited as 10-day notice + 10-day objection), with a trust-portal subscription option. Confirm the exact notice/objection terms against the DPA, and whether the canonical list should point to the Vanta trust portal.
HIPAA, BAA & PHI
🔶 Verify — Legal: Reported stance — Thread is not HIPAA compliant and does not represent itself as a HIPAA Business Associate; it is an IT service desk not designed to receive/store PHI, so any PHI exposure is incidental and out of intended use. Partners are responsible for keeping PHI out (recommended: an acceptable-use policy with clients). Thread signs BAAs only rarely, on its own paper as an MSA addendum. HIPAA evaluation reportedly planned after SOC 2 completes. Legal must approve any published HIPAA/BAA language.
DPA, Standard Contractual Clauses & DPF
🔶 Verify — Legal: Reported — Thread maintains a DPA incorporating the 2021 EU SCCs (Module 2 controller-to-processor, Module 3 sub-processor), governed under Republic of Ireland law, with a UK SCCs Addendum available; executed for EU/UK partners with a ~1–2 week turnaround. EU-US Data Privacy Framework (DPF) certification is reportedly pending (ITA application #B-04152), so the SCCs — not the DPF — are the transfer mechanism today. DPF status is time-sensitive; Legal must confirm before publishing.
Verification checklist
Route each item to its owner before publishing. Remove the DRAFT banner andnoindex only when all are cleared.
Sources: partner DDQ threads in #sales-engineering, #team-customer-success, and #team-product (Feb–Aug 2026). See
docs-gap-report.md gaps #3, #4, #6, #12, #14, #16 for the originating Slack evidence links.