GDPR
Policy alignedEU personal data handling commitments documented in our Privacy Policy and Data Processing Addendum.
coThink Trust Center
See what is protected, how it is governed, and what is still on the roadmap.
EU personal data handling commitments documented in our Privacy Policy and Data Processing Addendum.
California privacy rights and disclosures described in our Privacy Policy.
Point-in-time assessment of security control design.
Independent attestation of operating effectiveness of security controls over time.
Information security management system certification.
Current controls, planned work, and certification status.
Third-party vendors that may process data on behalf of coThink.
Audit reports when SOC 2 attestation is completed.
Implemented Partial Planned
| Vendor | Purpose | Category |
|---|---|---|
| Stripe | Billing | Payment processing |
| OpenRouter | Optional AI Routing | AI provider |
| OpenAI | Optional Customer AI Provider | AI provider |
| Anthropic | Optional Customer AI Provider | AI provider |
You do. coThink does not claim ownership of your prompts, messages, files, notes, workspace content, or session artifacts.
coThink does not use Customer Content to train third-party foundation models through its platform-improvement processes.
Not without the encryption keys. Decryption requires keys you control.
Yes. coThink supports data export capabilities so organizations can retrieve workspace content according to plan and configuration.
2026-07-06
Local passwords now follow NIST SP 800-63B (8–256 characters, no composition rules), compromised-password screening (local blocklist plus HIBP k-anonymity, fail closed), and bcrypt over a SHA-256 pre-hash. Documented on Identity, Application Security, Controls, and Security overview pages.
2026-06-24
Reorganized into Overview, Resources, Controls, Subprocessors, FAQ, and Updates. Added framework status cards, a control inventory, and grouped document links.
2026-06-23
Added dedicated Trust Center pages for encryption, identity, infrastructure, application security, availability, and privacy. Published security.txt and expanded subprocessors list.