thinQit|Security

|

Six pillars of trust

Built for the teams who can't afford mistakes.

thinQit protects customer and agent activity with TLS 1.3 in transit and AES 256 at rest, enterprise SSO with role based access control, immutable audit logs streamed to your SIEM, independent SOC 2 Type II and ISO 27001 audits, and a customer choice of data region.

01

Data in transit & at rest

Always encrypted

All traffic is TLS 1.3 with perfect forward secrecy. Data at rest is encrypted with AES 256, and customer keys are rotated automatically.

  • TLS 1.3 everywhere
  • AES 256 at rest
  • Automatic key rotation
  • Optional BYOK (bring your own key)
02

Access control

Granular by design

Enterprise SSO via SAML and OIDC, role based access control, and just in time approvals for sensitive actions. No shared credentials, ever.

  • SAML & OIDC SSO
  • Role based access control
  • SCIM user provisioning
  • Just in time approvals
03

Compliance

Built for enterprise

Independently audited against SOC 2 Type II and ISO 27001. GDPR and CCPA aligned by default, with DPAs available on request. Enterprise plans include a SOC 2 report and a signed DPA as standard.

  • SOC 2 Type II
  • ISO 27001
  • GDPR & CCPA ready
  • HIPAA available on Enterprise
04

Audit & observability

Every action, logged

Immutable audit trails for every user and agent action, streamed to your SIEM in real time. Search, export, and retain for as long as you need.

  • Immutable audit logs
  • Real time SIEM streaming
  • Export to Splunk / Datadog
  • Configurable retention
05

Continuous testing

Trust, but verify

Ongoing penetration testing, static and dynamic code analysis on every commit, and a public bug bounty with responsible disclosure.

  • Annual third party pentest
  • SAST + DAST on every PR
  • Public bug bounty
  • Dependency scanning
06

Data residency

Where your data lives

Choose the region your data is stored and processed in. Enterprise customers get dedicated tenants with isolated storage and compute.

  • Multi region availability
  • Dedicated enterprise tenants
  • Signed DPAs on request
  • Full data export at any time

Security FAQ

thinQit security, answered

Direct answers about encryption, access, auditing and data location.

How does thinQit encrypt customer data?

All traffic runs over TLS 1.3 with perfect forward secrecy, and data at rest is encrypted with AES 256. Customer keys rotate automatically, and Enterprise customers can bring their own key.

Which compliance standards has thinQit been audited against?

thinQit is independently audited against SOC 2 Type II and ISO 27001, and is GDPR and CCPA aligned by default. DPAs are available on request, and HIPAA support is available on Enterprise.

How is access to a workspace controlled?

Access uses enterprise SSO via SAML and OIDC, role based access control and SCIM user provisioning. Sensitive actions require just in time approvals, and shared credentials are never used.

Can we see what an AI agent did in our workspace?

Yes. Every user and agent action is written to an immutable audit log that streams to your SIEM in real time. Logs can be searched, exported to Splunk or Datadog, and retained for a configurable period.

Where is thinQit data stored and processed?

Customers choose the region their data is stored and processed in. Enterprise customers receive dedicated tenants with isolated storage and compute, and a full data export is available at any time.

Explore related thinQit pages

Get NIS2 ready with Nisha Meet the AI teammates Compare plans, seats and SSO About Thinqit B.V. See how Codex builds and reviews work Read the security guardrails guide

Security you can show, not just claim.

Start your audit today.

Request a SOC 2 report, review our DPA, or spin up a trial tenant — all in under five minutes.

Talk to security