Security
Project isolation
Every project's content carries a project identifier, and every read applies it as a mandatory filter — in the database and in the vector index alike. One project cannot retrieve or cite another project's content, including inside the same organization. The same scoping is applied on writes, so content cannot land in the wrong project either.
Credentials
Credentials for connected tools — OAuth tokens, API keys — are encrypted before storage. Secrets you paste into connector settings, such as webhook signing secrets, are write-only: the API accepts them and never returns them, so they cannot be read back out through the interface by anyone, including your own administrators.
Traffic is encrypted in transit with TLS. Sign-in is handled by session cookies that browser JavaScript cannot read.
Access control and write identity
Membership is per project, with roles that separate reading from administering.
Which account a write-back appears to come from depends on the connector. Some connect per person, so each member's writes carry their own authorization. Some connect as a service account, so writes arrive from a bot identity. The rest — most of them today — use one shared connection authorized by whoever installed it, which means a write triggered by another member is performed with that installer's access and is attributed in the body of the message rather than by the account. If that distinction matters for a tool you are connecting, ask us which mode it uses before you install it.
Controlled write-back
Actions that change something in your tools run under the project's policy: allowed, denied, or held for human approval. Approval requests carry the proposed change, and the decision — who, when, what — is recorded.
Audit trail
The Service keeps a write-once audit log: the actor, the action, the affected resource, and the before and after state. It is queryable in the app, survives deletion of the project it describes, and is removed only on the retention period a project chooses to set.
What we do not claim
We hold no third-party security certification — no SOC 2, no ISO 27001. Answering your questions sends excerpts of your content to external model providers under their standard terms (see the Privacy Policy), so “your data never leaves” is not a claim we make. Backups are operated manually rather than on an automated, independently verified rotation. We would rather you know this than discover it during a pilot.
Reporting a vulnerability
If you believe you have found a security issue, report it through the contact page or to hello@threadory.ai rather than filing a public issue. Tell us what you found and how to reproduce it; we will confirm receipt and keep you posted while we fix it.