Think It Through
Think It Through
Security posture

Early-stage, private by default, and honest about compliance.

Think It Through does not have SOC 2, HIPAA, or ISO 27001 certification yet. Until those audits are earned, we publish the controls we do have and keep the roadmap clear.

Current controls

Recordings are private to the owner or workspace until shared.
Share links use unguessable IDs, and owners can revoke a link or require a viewing password at any time.
Recording ownership, billing, integrations, and push actions are checked server-side by tenant.
Slack, Notion, and Linear credentials are encrypted at rest with AES-256-GCM; share passwords are scrypt-hashed.
Uploads, imports, and webhooks use allowlists and signature checks where applicable.
Viewer analytics use anonymous browser IDs and salted IP hashes instead of raw viewer IP storage.

Roadmap before enterprise compliance

Rotate-link and verified-viewer (email) share options.
Workspace audit log for recording, comment, integration, billing, and sync events.
Retention controls for recordings and transcripts.
Subprocessor page and DPA template.
SSO, domain capture, and SCIM when team demand justifies it.
SOC 2 Type I once enterprise demand is real, then Type II after controls run over time.

Security-readiness service boundary

A service inquiry is not authorization to test a system. Any non-passive work requires a written scope naming the assets, exclusions, permitted techniques, test window, and authorized owner. The service does not include denial-of-service, brute force, or social engineering.