Security Whitepaper
Last updated: June 2026
1. Architecture overview
Threadsovereign is a multi-tenant SaaS application. The marketing site (threadsovereign.co.uk) is separated from the production application (threadsovereign.io). Customer data is stored in UK data centres via Supabase (London region), with encryption in transit (TLS 1.2+) and at rest.
2. Identity and access
- Role-based access control within each organisation workspace
- Session management with secure cookie handling on the app domain
- Enterprise SSO available on request (SAML/OIDC)
- API keys restricted to Enterprise tier with scoped permissions
3. Data handling and separation
Building safety documentation uploaded by customers remains the property of the customer. We do not use customer compliance data to train third-party AI models. Audit logs record material actions on safety-critical records.
Customer building safety records are stored in UK data centres via Supabase (London region). The production application (threadsovereign.io) is separated from the marketing site (threadsovereign.co.uk). Operator tenant data is never shared across organisations without explicit authorisation. Limited personal data may be processed by sub-processors outside the UK for email, SMS, payments, and e-signatures — see our sub-processor list.
4. Operational security
- Automated dependency and known-vulnerability scanning on application codebases
- Segregation between staging and production environments
- Daily backups with 30-day point-in-time recovery
- Incident response process with customer notification for data breaches
Automated scanning and architectural controls are not a substitute for an independent penetration test. See our assurance programme below.
5. Assurance programme (not yet completed)
Threadsovereign publishes policies and technical controls in place today. The items below are part of our go-live assurance programme and are not yet complete — ask security@threadsovereign.co.uk for current status before procurement sign-off.
- Independent penetration test. Not yet completed. OWASP Top 10 minimum scope with an external tester is planned.
- Data Protection Impact Assessment (DPIA). Not yet completed. Required for resident and PEEP special-category data processing. An internal draft exists; DPO/counsel sign-off is outstanding.
- Legal review — Terms & DPA. Not yet completed. External counsel review for BSA-regulated building contexts is required.
- Formal security review. Not yet scheduled. Covers environment variables, secrets handling, and auth configuration.
6. Certifications
We are preparing Cyber Essentials (basic) for IASME submission and building an ISMS foundation toward ISO 27001. None of the items below are certified today — ask security@threadsovereign.co.uk for current status before procurement sign-off.
- Cyber Essentials (basic). Internal readiness pack prepared for IASME self-assessment submission — not yet certified. Do not treat as Cyber Essentials certified until a certificate is issued.
- Cyber Essentials Plus. Planned after Cyber Essentials (basic). Certification has not commenced.
- ISO 27001. ISMS foundation documentation in progress. Formal certification audit has not commenced.
- SOC 2 Type II. Planned for enterprise buyers. Certification has not commenced.
Current achieved items are listed in our Trust Centre.
7. Contact
Security enquiries and responsible disclosure: security@threadsovereign.co.uk