GDPR
Policy alignedEU personal data handling commitments documented in our Privacy Policy and Data Processing Addendum.
Trust Center
Security, privacy, and compliance documentation for vendor reviews. Policies, controls, subprocessors, and certification status in one place.
EU personal data handling commitments documented in our Privacy Policy and Data Processing Addendum.
California privacy rights and disclosures described in our Privacy Policy.
Point-in-time assessment of security control design.
Independent attestation of operating effectiveness of security controls over time.
Healthcare data handling support and BAA availability for eligible deployments.
Information security management system certification.
Current controls, planned work, and certification status.
Third-party vendors that may process data on behalf of coThink.
Audit reports when SOC 2 attestation is completed.
Implemented Planned
| Vendor | Purpose | Category |
|---|---|---|
| Stripe | Billing | Payment processing |
| OpenRouter | Optional AI Routing | AI provider |
| OpenAI | Optional Customer AI Provider | AI provider |
| Anthropic | Optional Customer AI Provider | AI provider |
You do. coThink does not claim ownership of your prompts, messages, files, notes, workspace content, or session artifacts.
coThink does not use Customer Content to train third-party foundation models through its platform-improvement processes.
Not without the encryption keys. Decryption requires keys you control.
Yes. coThink supports data export capabilities so organizations can retrieve workspace content according to plan and configuration.
2026-06-24
Reorganized into Overview, Resources, Controls, Subprocessors, FAQ, and Updates. Added framework status cards, a control inventory, and grouped document links.
2026-06-23
Added dedicated Trust Center pages for encryption, identity, infrastructure, application security, availability, and privacy. Published security.txt and expanded subprocessors list.
2026-06-23
SAML SSO service-provider flow, SCIM 2.0 user provisioning, and primary passkey sign-in are available for entitled organizations.