ThoughtSpot Security Portal

Welcome to **ThoughtSpot's Security Portal!** At ThoughtSpot, our mission is to help everyone create a more fact-driven world. To achieve this, we recognize that trust is the essential foundation. Our Security Portal provides you with access to the information you need to validate our commitment to the security and privacy of your data. You can easily access and download information about our comprehensive security program and posture, key compliance certifications, and how we use artificial intelligence to bring you more insight into your data. We aim to be transparent, so you can be confident in ThoughtSpot's security and data protection practices, allowing you to focus on using AI-powered analytics to drive your organization forward. To learn more about our security and privacy practices, visit our Trust Center at [www.thoughtspot.com/trust](https://www.thoughtspot.com/trust).

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
ThoughtSpot Security Portal
Header background

ThoughtSpot Security Portal

Welcome to ThoughtSpot's Security Portal!

At ThoughtSpot, our mission is to help everyone create a more fact-driven world. To achieve this, we recognize that trust is the essential foundation. Our Security Portal provides you with access to the information you need to validate our commitment to the security and privacy of your data.

You can easily access and download information about our comprehensive security program and posture, key compliance certifications, and how we use artificial intelligence to bring you more insight into your data.

We aim to be transparent, so you can be confident in ThoughtSpot's security and data protection practices, allowing you to focus on using AI-powered analytics to drive your organization forward.

To learn more about our security and privacy practices, visit our Trust Center at www.thoughtspot.com/trust.

Access control

Policies and processes that govern user authentication, authorization, account management, and access reviews to ensure only authorized personnel can access systems and data.

Multi-factor authentication

All access to critical systems, including production environments and administrative accounts, requires multi-factor authentication, providing a strong layer of protection against unauthorized access.

Role-based access control

User access is provisioned and reviewed based on defined roles and responsibilities, ensuring least privilege and clear segregation of duties across all environments and applications.

Quarterly and annual access reviews

Access to key systems is reviewed quarterly and annually to ensure that permissions remain appropriate to each employee's job function and terminated access is correctly enforced.

Immediate access termination

User access to all platforms is removed within one business day of termination, reducing the risk of unauthorized resource use by former personnel.

Password policy enforcement

Strong password parameters are enforced for directory, VPN, and SSO services, requiring complex passwords, regular rotation, and prevention of reuse to reduce credential-based risks.

Administrative and privileged access management

Administrative access to critical systems is tightly restricted and logged, with approvals required and usage tracked for all privileged operations to deter and detect misuse.

Access provisioning and deprovisioning workflow

All access changes are tracked via workflow systems that require documented approvals for onboarding and elevated privileges, ensuring transparency and auditability for all account updates.

Accessibility compliance

System design and product features promote accessibility for persons with disabilities, supporting legal requirements and inclusive user experience.

WCAG and Section 508 conformance testing

Products are tested against recognized accessibility standards using both automated tools and expert manual review, supporting broad adoption and regulatory compliance.

Support for assistive technologies

Key pages and workflows are tested with widely used assistive technologies to ensure compatibility and functional access for all users.

Cross-platform accessibility validation

Manual and automated testing spans multiple major browsers and operating systems, increasing certainty that accessibility features function for the widest audience possible.

Accessibility issue tracking and remediation

Accessibility issues are documented, prioritized, and resolved based on testing and user feedback to continually improve usability for diverse audiences.

Automated and manual accessibility review

Accessibility is assessed through automated scanning and manual reviews workflows, screen readers, and keyboard navigation.

AI Governance

Policies and oversight mechanisms for safe, responsible, and ethical use of artificial intelligence and machine learning in product features.

Model access control

Access to AI models and related infrastructure is tightly controlled and changes must be tested and approved before production deployment, ensuring only authorized personnel can influence AI behavior.

AI-enabled feature approval and testing

Changes to AI-powered services are subject to testing and formal management approval prior to production, lowering risk of drift or unintended impact to customer systems.

Vendor and partner AI risk review

Vendors supporting AI features are annually assessed for security and compliance risk, and controls over model hosting, data protection, and incident response are enforced.

Application security

Practices, tools, and reviews embedded into the development lifecycle to minimize vulnerabilities and deliver secure software.

Secure software development lifecycle

The SDLC is based on industry best practices, integrating security requirements, code reviews, and vulnerability scanning throughout all stages of development.

Automated vulnerability scanning and code analysis

Static and dynamic scans, including software composition analysis, are performed before major releases to detect and remediate vulnerabilities prior to production deployment.

Peer code review and build testing

Every code change is subject to peer review and build testing before being merged or deployed, significantly reducing the risk of introducing exploitable defects.

Environment segregation

Production, staging, and development environments are logically separated with strong access controls, supporting both availability and data protection.

Patch management process

Routine and emergency patches are prioritized and applied according to a risk-based schedule to maintain all systems at current security levels.

Change management policy

A formal change management program requires all infrastructure, configuration, and product changes to be tested, reviewed, and approved prior to implementation.

Non-production data protection

No confidential or customer data is used in non-production environments; only synthetic data is allowed, preventing accidental exposure of sensitive information during testing and development.

Compliance and auditing

Independent attestations and internal procedures demonstrating alignment with industry regulations and customer requirements.

SOC 1 Type II, SOC 2 Type II, and SOC 3 reports

Undergoes regular independent audits attesting to the effectiveness of controls over security, availability, processing integrity, and confidentiality, providing assurance to customers and auditors.

ISO/IEC 27001:2022 certification

Maintains an ISO 27001:2022 certified information security management system, demonstrating a global standard for information security governance.

Annual risk assessments

Performs scheduled risk assessments covering laws, regulations, and operational threats, with documented mitigation and continual improvement actions.

Vendor and subservice organization monitoring

Vendors and subservice organizations undergo annual risk assessments and are required to meet security, availability, and confidentiality standards, with corrective action processes in place.

Audit logging and review

Comprehensive system and application logs are collected, protected, and reviewed for compliance and forensic purposes, supporting full accountability.

Business continuity

Redundant systems, backup processes, and tested plans enable consistent service delivery and rapid recovery from disruptive events.

Business continuity and disaster recovery planning

Documented plans exist for all critical systems, reviewed and tested at least annually, to ensure the organization can rapidly recover from disaster scenarios and minimize downtime.

Automated and encrypted backups

Production databases and infrastructure are backed up daily with strong encryption, and backup systems proactively alert IT to failures for immediate remediation.

Regular restore testing

Annual restore tests are performed for all critical systems to verify the successful restoration and integrity of backup data.

Geographic redundancy

Cloud infrastructure and key applications are deployed across multiple zones and regions, supporting high availability even during localized failures.

Environmental controls and power resilience

Key data centers have uninterrupted power supplies, regularly maintained backup generators, and annual fire suppression system tests, reducing risk of downtime from environmental or utility failure.

Data security

Measures and policies to safeguard sensitive data at rest, in transit, and during lifecycle management, ensuring data confidentiality and integrity.

Encryption at rest

All customer and company data stored in cloud environments is encrypted at rest using industry best practices to protect against unauthorized access or data breaches.

Encryption in transit

All data transmissions over public and internal networks are encrypted using secure protocols, ensuring information remains confidential during transfer.

Secure encryption key management

Encryption keys are securely managed and access is restricted to authorized personnel, minimizing the risk of key compromise and unauthorized decryption.

Data loss prevention

A data loss prevention solution is implemented across endpoints and critical systems to detect and prevent unauthorized data movement or leakage.

Formal data retention and destruction policy

Data retention and deletion processes are governed by documented policies, ensuring confidential information is properly retained and disposed of in accordance with legal and contractual obligations.

Data classification standards

Comprehensive policies define data classification and handling procedures, defaulting unspecified data to 'confidential' to maintain stringent information protection controls.

Employee security

People-focused security controls ensure all staff are screened, trained, and held accountable to robust security and ethical standards.

Background checks prior to employment

Background verification is required for new employees and contractors prior to access, minimizing risk related to personnel with access to sensitive systems.

Annual security awareness training

All employees complete security awareness education annually, reinforcing a culture of vigilance and compliance throughout the organization.

Annual secure code training for developers

Specialized training for staff responsible for software development is mandatory every year, raising security maturity and reducing product vulnerabilities.

Formal disciplinary process

Non-compliance with security and ethical standards is addressed through a documented disciplinary process up to and including termination, ensuring accountability at all levels.

Annual performance reviews

Employee performance, including security responsibilities, is reviewed annually to ensure ongoing alignment with role and company values.

Incident response

Comprehensive detection, escalation, and remediation processes for security events to minimize impact and inform stakeholders.

Incident response plan

A documented incident management process includes root cause analysis, defined escalation paths, corrective action procedures, and communications for all incidents involving security, availability, integrity, or confidentiality.

24/7 security monitoring and alerting

Automated monitoring solutions continuously scan environments for real-time security events, generating alerts to enable rapid identification and response.

Intrusion detection and prevention

An advanced system monitors for unauthorized network and system activity, providing ongoing protection and automated escalation for all abnormal events.

Ticketing and post-incident review

Every alert and incident is logged, tracked through an integrated ticketing system, and reviewed to ensure comprehensive resolution and lessons learned are incorporated.

Secure anti-malware deployment

Anti-virus, anti-malware, and endpoint security solutions are deployed with real-time response to infections on user devices and production servers, mitigating malware risk.

Infrastructure security

Controls to harden, monitor, and secure core cloud and network infrastructure to prevent unauthorized access and service disruption.

Network segmentation and isolation

Production, development, and staging environments are isolated using logical access controls, preventing lateral movement and supporting defense-in-depth strategy.

Firewall and network device management

Firewalls, security groups, and related devices are annually reviewed and monitored to ensure only authorized network traffic is permitted and all configurations remain secure.

Web application firewall (WAF) deployment

WAFs and similar controls are deployed at key ingress points to prevent web-based threats and unauthorized access attempts on internet-facing services.

DDoS protection and monitoring

DDoS mitigation services and automated detection protect against large-scale denial of service attacks, preserving availability and reliability of cloud services.

Vulnerability management program

Monthly scanning and prompt remediation of high or critical vulnerabilities in infrastructure and applications maintain a strong defensive posture.

Monitoring and logging

Continuous and centralized monitoring of system and application activity to detect, investigate, and remediate anomalies or threats.

Centralized logging solution

All key platforms aggregate system and application logs to a secure, centralized platform that restricts modification and supports comprehensive audit and forensic support.

Proactive anomaly detection

Automated solutions monitor for anomalous behavior, capacity issues, and potential security events, generating alerts for timely investigation and response.

Log access control

Log data is protected from unauthorized modification or deletion and access is limited to individuals with demonstrated business need.

Ticketing for alert remediation

Security and anomaly alerts automatically generate tickets, ensuring all events are tracked from detection through resolution with full accountability.

Physical security

Multi-layered facility security controls to protect physical equipment, data centers, and supporting infrastructure from intrusion and unauthorized access.

Electronic badge access system

Physical access to sensitive spaces requires electronic badge authentication and is limited strictly according to job function, ensuring only authorized personnel may enter restricted areas.

Security guard and video surveillance

Facilities are monitored by security personnel and video surveillance with footage retained for at least 30 days, providing a thorough deterrent and rapid response to any physical risk.

Quarterly physical access reviews

Regular reviews of all facility access permissions ensure that only current, authorized staff retain entry rights and that any discrepancies are promptly addressed.

Prompt revocation of access after termination

Physical access badges and credentials are disabled within one business day following employee termination, restricting former personnel from entering secure facilities.

Visitor management protocol

All visitors and temporary personnel must be registered, photographed, and verified with government-issued ID before gaining access, preserving a secure audit trail.

Security governance

Leadership commitment, policies, and organizational structure that ensure enforceable, documented, and maintained security practices across the business.

Management oversight and board engagement

Board of Directors and executive leadership regularly review operations and risks, ensuring high-level accountability for information security and compliance.

Formal information security policy

Policies covering security, incident response, and data classification are maintained, formally reviewed and approved annually, and communicated across the organization.

RASCI and clear accountability

Roles and responsibilities for security are clearly defined and maintained, ensuring all security-related activities have identified accountability, supporting robust operational control.

Policy change management

Well-documented processes exist for any security policy update, requiring formal communication and re-acknowledgment by employees after significant changes.

Organizational chart and functional separation

An up-to-date, accessible organizational chart ensures all employees understand reporting lines and role-based responsibility for security and compliance.

Third-party management

Structured processes manage risk from all vendors, subprocessors, and partners that may access, process, or support company or customer data.

Annual vendor risk assessment

All third parties and subprocessors are reviewed annually to determine risk level, with appropriate security assessment, monitoring, or certification review performed based on the risk assigned.

Security requirements in contracts

All key vendor and partner agreements require adherence to security, availability, and confidentiality commitments aligned with company policies and customer expectations.

New vendor due diligence

Before onboarding, vendors that host or process data must undergo a risk assessment to ensure compliance with the organization’s security standards.

Subservice organization monitoring

Critical subservice providers are monitored through the review of their SOC reports or through direct security due diligence, ensuring continued alignment with company commitments.

Contract review and approval by legal and management

All third-party contracts are reviewed and approved by management and legal prior to execution, ensuring all security and compliance requirements are met.