Security

Last updated: August 25, 2025

This page outlines our security posture and practices. ThinklytixAI is an AI-powered analytics and conversational intelligence platform built to protect data privacy, security, and client control.

We never use client data to train, fine-tune, or improve any Large Language Model (LLM) — public or private. All AI interactions occur in real-time using secure, ephemeral processing; data is never persisted outside the client’s environment.

Standards & Compliance

  • SOC 2 readiness and best practices.
  • Encryption in transit (TLS) and at rest where applicable.
  • Access controls based on least privilege and role-based authorization.

Protecting Your Data

  • Network segmentation and monitoring.
  • Vulnerability scanning and timely patching.
  • Routine backups and recovery testing.

Core Principles

  1. Data Ownership – Clients fully own their raw data, derived datasets, and generated insights.
  2. No Model Training on Client Data – LLMs operate only in stateless inference mode; no retention, fine-tuning, or reuse occurs.
  3. No Cross-Client Data Exposure – Queries and responses are isolated per client.
  4. Controlled Access – Access governed by RBAC and MFA.
  5. Transparency – Clients may review processing logs and configurations.

Responsible Disclosure

If you believe you’ve found a security issue, please contact us at security@thinklytix.ai. We appreciate responsible disclosure.