Compliance

Compliance overview

Our certifications, reports, and where our data lives. For the full picture of how we protect data, see Security & Trust.

Last updated: July 1, 2026
SOC 2 Type II
ISO 27001
GDPR
HIPAA

Certifications & attestations

We maintain a SOC 2 Type II attestation and ISO 27001 certification, renewed on an annual cycle by independent auditors. We support GDPR obligations and offer a HIPAA Business Associate Agreement to eligible customers.

Reports available

Under NDA, we share our current SOC 2 Type II report, penetration-test summary, and security whitepaper. Request access through your account team or the contact below.

Subprocessors

We publish a current list of subprocessors, the service each provides, and its processing location. We provide advance notice of changes so customers can review new subprocessors.

Data residency

Customer data is hosted in the region you select at onboarding, with encryption at rest and in transit. Cross-region processing, where needed, uses lawful transfer mechanisms described in our DPA.

Reporting a vulnerability

We run a coordinated disclosure program. If you believe you've found a vulnerability, email security@thruline.co and we'll respond promptly. Please don't access data that isn't yours while testing.