Trust Center

coThink Trust Center

Security, privacy, and compliance documentation for vendor reviews. Policies, controls, subprocessors, and certification status in one place.

Security contact: [email protected]

Compliance

View all

GDPR

Policy aligned

EU personal data handling commitments documented in our Privacy Policy and Data Processing Addendum.

CCPA / CPRA

Policy aligned

California privacy rights and disclosures described in our Privacy Policy.

SOC 2 Type I

Readiness in progress

Point-in-time assessment of security control design.

SOC 2 Type II

Roadmap

Independent attestation of operating effectiveness of security controls over time.

HIPAA

Planning

Healthcare data handling support and BAA availability for eligible deployments.

ISO 27001

Roadmap

Information security management system certification.

Resources

View all

Controls

View all

Last reviewed 2026-06-24

Implemented Planned

Subprocessors

View all
Vendor Purpose Category
Stripe Billing Payment processing
OpenRouter Optional AI Routing AI provider
OpenAI Optional Customer AI Provider AI provider
Anthropic Optional Customer AI Provider AI provider

FAQ

View all

Who owns my data?

You do. coThink does not claim ownership of your prompts, messages, files, notes, workspace content, or session artifacts.

Does coThink train AI models on my content?

coThink does not use Customer Content to train third-party foundation models through its platform-improvement processes.

Can coThink read encrypted rooms?

Not without the encryption keys. Decryption requires keys you control.

Can I export my data?

Yes. coThink supports data export capabilities so organizations can retrieve workspace content according to plan and configuration.

Updates

View all

Trust Center last updated 2026-06-24

2026-06-24

Trust Center overhaul

Reorganized into Overview, Resources, Controls, Subprocessors, FAQ, and Updates. Added framework status cards, a control inventory, and grouped document links.

2026-06-23

Trust Center expansion

Added dedicated Trust Center pages for encryption, identity, infrastructure, application security, availability, and privacy. Published security.txt and expanded subprocessors list.

2026-06-23

Enterprise identity controls

SAML SSO service-provider flow, SCIM 2.0 user provisioning, and primary passkey sign-in are available for entitled organizations.