> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getthread.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust & security

> One place to answer a partner security review: hosting and data residency, AI data handling, certifications, tenant isolation, availability, data deletion, subprocessors, HIPAA, and data-processing agreements.

<Warning>
  **DRAFT — NOT FOR PUBLICATION. Pending Product/Legal/Security verification.**

  This page consolidates answers Thread's team has given to partner security questionnaires (DDQs) in Slack. **Every claim marked 🔶 is unverified** and must be confirmed by the named owner before this page is published. Several items are **time-sensitive** (certification dates, DPF status, the subprocessor list) and will need a review cadence. When this page is approved, remove this banner and the `noindex` flag in the frontmatter. See the [Verification checklist](#verification-checklist) at the bottom.
</Warning>

This hub is designed to let a CSM or AE answer a partner's security review from a single link. It points to the security pages that already exist and gathers the recurring due-diligence answers that don't yet have a home.

## Already documented

These topics are already covered — link to them directly:

<CardGroup cols={2}>
  <Card title="Data & encryption" icon="lock" href="/security-billing/data-encryption">
    What Thread stores, at-rest/in-transit encryption, and the data-residency FAQ (US-only hosting).
  </Card>

  <Card title="Magic AI privacy & security" icon="shield-halved" href="/security-billing/magic-ai-privacy-security">
    Azure OpenAI isolation, no data retention, and no model training on customer data.
  </Card>

  <Card title="Sub-processors" icon="sitemap" href="/security-billing/list-of-sub-processors">
    The current sub-processor list and each provider's purpose.
  </Card>

  <Card title="IP restrictions" icon="network-wired" href="/security-billing/what-if-my-organization-has-ip-restrictions">
    Allowlisting guidance for restricted networks.
  </Card>
</CardGroup>

## Data hosting & residency

Thread is a single-region, **US-only** platform: the application database and infrastructure run in AWS US-East, with Microsoft-side services on Azure US-East. There is no per-partner or per-client residency selection. This is already documented in the [Data & encryption residency FAQ](/security-billing/data-encryption#data-residency-faq).

> **🔶 Verify — Legal + Product:** Confirm the customer-facing statement that Thread does **not** offer an EU/EEA data-residency option, and that cross-border transfers are governed by the EU SCCs in the DPA (see [DPA & data transfers](#dpa-standard-contractual-clauses--dpf) below).

## AI & data handling

Covered in depth on [Magic AI privacy & security](/security-billing/magic-ai-privacy-security): customer content is processed in memory only, never retained, and never used to train, retrain, or improve any model (Azure OpenAI and AWS Bedrock run on locked-down private instances).

> **🔶 Verify — Product:** Add an explicit **"Knowledge ≠ Training"** clarification — building a knowledge base from a partner's data enriches answers with context at retrieval time and is isolated per workspace/end-customer; it does **not** train a model. Confirm wording before publishing.

## Certifications & audits

> **🔶 Verify — Security + Legal (time-sensitive):** All figures below are drafts from Slack and must be confirmed and kept current.

* **SOC 2 Type II** — reported as *in progress* (Security / Common Criteria, observation period started Jan 1 2026), under independent CPA review by Prescient Assurance; **report not yet issued**. Do not state or imply Thread "is SOC 2 certified" until the report is issued. Bridge/engagement letters are shared under NDA.
* **Penetration testing** — reported as an annual third-party pen test (Optiv, most recent May 2025), quarterly scans, with 30-day (critical) / 120-day (high) remediation targets. Executive summary under NDA.
* **ISO 27001** — reported as **not certified**, but with an ISMS aligned to ISO 27001/27005 and NIST 800-30. Confirm the exact "aligned, not certified" phrasing.

## Tenant isolation

> **🔶 Verify — Security/Engineering:** Reported as multi-tenant isolation enforced server-side on every read/write, with a central authorization layer evaluating identity + tenant scope. Confirm the customer-safe description (no internal implementation detail).

## Availability & resilience

> **🔶 Verify — Engineering:** Draft figures below need confirmation and a source of truth.

* Reported uptime **> 99.9%** with hot failover; hosting RTO/RPO cited as 5 days / 10 days; annual DR testing.
* **No customer-facing response-time SLA** today — confirm this is the stance to publish.
* **PSA-outage resilience:** if a PSA or downstream system is down, Thread keeps receiving messages and **queues outbound writes**, posting them once service is restored (reported as no data loss). Confirm.

## Data retention, export & deletion

> **🔶 Verify — Legal + Product:** Reported as data deleted within **90 days** of termination, with export available in **CSV/JSON**. Confirm the retention window, the deletion process, and the export mechanism.

## Audit logging

> **🔶 Verify — Product:** Reported that every AI/tool action is posted to the ticket and can optionally sync to the PSA, but there is **no public audit-log API** yet (customers pull from the PSA for a SIEM). Confirm current state before publishing.

## Sub-processors & change notification

The maintained list lives on [Sub-processors](/security-billing/list-of-sub-processors) (currently dated August 2026 and appears current).

> **🔶 Verify — Legal:** Document the **change-notification mechanism** — reported as advance notice of any new/replacement sub-processor with a window to object before it takes effect (cited as 10-day notice + 10-day objection), with a trust-portal subscription option. Confirm the exact notice/objection terms against the DPA, and whether the canonical list should point to the Vanta trust portal.

## HIPAA, BAA & PHI

> **🔶 Verify — Legal:** Reported stance — Thread is **not HIPAA compliant** and does not represent itself as a HIPAA Business Associate; it is an IT service desk not designed to receive/store PHI, so any PHI exposure is incidental and out of intended use. Partners are responsible for keeping PHI out (recommended: an acceptable-use policy with clients). Thread signs BAAs only rarely, on its own paper as an MSA addendum. HIPAA evaluation reportedly planned after SOC 2 completes. **Legal must approve any published HIPAA/BAA language.**

## DPA, Standard Contractual Clauses & DPF

> **🔶 Verify — Legal:** Reported — Thread maintains a DPA incorporating the 2021 EU SCCs (Module 2 controller-to-processor, Module 3 sub-processor), governed under Republic of Ireland law, with a UK SCCs Addendum available; executed for EU/UK partners with a \~1–2 week turnaround. **EU-US Data Privacy Framework (DPF) certification is reportedly pending** (ITA application #B-04152), so the SCCs — not the DPF — are the transfer mechanism today. DPF status is time-sensitive; Legal must confirm before publishing.

## Verification checklist

Route each item to its owner before publishing. Remove the DRAFT banner and `noindex` only when all are cleared.

|  # | Topic                                                   | Owner            | Time-sensitive? |
| -: | ------------------------------------------------------- | ---------------- | :-------------: |
|  1 | No EU residency + SCC transfer statement                | Legal + Product  |        —        |
|  2 | "Knowledge ≠ Training" wording                          | Product          |        —        |
|  3 | SOC 2 Type II status & issuance date                    | Security + Legal |        ✅        |
|  4 | Pen-test vendor, cadence, remediation SLAs              | Security         |        ✅        |
|  5 | ISO "aligned, not certified" phrasing                   | Security         |        —        |
|  6 | Tenant-isolation customer-safe description              | Security/Eng     |        —        |
|  7 | Uptime, RTO/RPO, DR testing, SLA stance                 | Engineering      |        —        |
|  8 | PSA-outage queueing behavior                            | Engineering      |        —        |
|  9 | Retention (90d), export (CSV/JSON), deletion process    | Legal + Product  |        —        |
| 10 | Audit-logging behavior + no public API                  | Product          |        —        |
| 11 | Sub-processor notice/objection terms + canonical source | Legal            |        ✅        |
| 12 | HIPAA / BAA / PHI stance and language                   | Legal            |        —        |
| 13 | DPA / EU SCCs / UK Addendum / DPF status                | Legal            |        ✅        |

*Sources: partner DDQ threads in #sales-engineering, #team-customer-success, and #team-product (Feb–Aug 2026). See `docs-gap-report.md` gaps #3, #4, #6, #12, #14, #16 for the originating Slack evidence links.*


## Related topics

- [Thread's SOC 2 and compliance status](/security-billing/soc-2-and-compliance-status.md)
- [B2B Collaboration Setup](/skill-library/m365-administration/b2b-collaboration-setup.md)
- [Security & Compliance Owner](/start-here/roles/security-compliance-owner.md)
