coThink Trust Center

Trust should be
inspectable.

See what is protected, how it is governed, and what is still on the roadmap.

Security contact: [email protected]

Compliance

View all

GDPR

Policy aligned

EU personal data handling commitments documented in our Privacy Policy and Data Processing Addendum.

CCPA / CPRA

Policy aligned

California privacy rights and disclosures described in our Privacy Policy.

SOC 2 Type I

Roadmap

Point-in-time assessment of security control design.

SOC 2 Type II

Roadmap

Independent attestation of operating effectiveness of security controls over time.

ISO 27001

Roadmap

Information security management system certification.

Resources

View all

Controls

View all

Last reviewed 2026-07-06

Implemented Partial Planned

Subprocessors

View all
Vendor Purpose Category
Stripe Billing Payment processing
OpenRouter Optional AI Routing AI provider
OpenAI Optional Customer AI Provider AI provider
Anthropic Optional Customer AI Provider AI provider

FAQ

View all

Who owns my data?

You do. coThink does not claim ownership of your prompts, messages, files, notes, workspace content, or session artifacts.

Does coThink train AI models on my content?

coThink does not use Customer Content to train third-party foundation models through its platform-improvement processes.

Can coThink read encrypted rooms?

Not without the encryption keys. Decryption requires keys you control.

Can I export my data?

Yes. coThink supports data export capabilities so organizations can retrieve workspace content according to plan and configuration.

Updates

View all

Trust Center last updated 2026-07-06

2026-07-06

NIST SP 800-63B password policy

Local passwords now follow NIST SP 800-63B (8–256 characters, no composition rules), compromised-password screening (local blocklist plus HIBP k-anonymity, fail closed), and bcrypt over a SHA-256 pre-hash. Documented on Identity, Application Security, Controls, and Security overview pages.

2026-06-24

Trust Center overhaul

Reorganized into Overview, Resources, Controls, Subprocessors, FAQ, and Updates. Added framework status cards, a control inventory, and grouped document links.

2026-06-23

Trust Center expansion

Added dedicated Trust Center pages for encryption, identity, infrastructure, application security, availability, and privacy. Published security.txt and expanded subprocessors list.