Security
Last updated: August 25, 2025
This page outlines our security posture and practices. ThinklytixAI is an AI-powered analytics and conversational intelligence platform built to protect data privacy, security, and client control.
We never use client data to train, fine-tune, or improve any Large Language Model (LLM) — public or private. All AI interactions occur in real-time using secure, ephemeral processing; data is never persisted outside the client’s environment.
Standards & Compliance
- SOC 2 readiness and best practices.
- Encryption in transit (TLS) and at rest where applicable.
- Access controls based on least privilege and role-based authorization.
Protecting Your Data
- Network segmentation and monitoring.
- Vulnerability scanning and timely patching.
- Routine backups and recovery testing.
Core Principles
- Data Ownership – Clients fully own their raw data, derived datasets, and generated insights.
- No Model Training on Client Data – LLMs operate only in stateless inference mode; no retention, fine-tuning, or reuse occurs.
- No Cross-Client Data Exposure – Queries and responses are isolated per client.
- Controlled Access – Access governed by RBAC and MFA.
- Transparency – Clients may review processing logs and configurations.
Responsible Disclosure
If you believe you’ve found a security issue, please contact us at security@thinklytix.ai. We appreciate responsible disclosure.