ThoughtSpot Security Portal

Welcome to **ThoughtSpot's Security Portal!** At ThoughtSpot, our mission is to help everyone create a more fact-driven world. To achieve this, we recognize that trust is the essential foundation. Our Security Portal provides you with access to the information you need to validate our commitment to the security and privacy of your data. You can easily access and download information about our comprehensive security program and posture, key compliance certifications, and how we use artificial intelligence to bring you more insight into your data. We aim to be transparent, so you can be confident in ThoughtSpot's security and data protection practices, allowing you to focus on using AI-powered analytics to drive your organization forward. To learn more about our security and privacy practices, visit our Trust Center at [www.thoughtspot.com/trust](https://www.thoughtspot.com/trust).

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
ThoughtSpot Security Portal
Header background

ThoughtSpot Security Portal

Welcome to ThoughtSpot's Security Portal!

At ThoughtSpot, our mission is to help everyone create a more fact-driven world. To achieve this, we recognize that trust is the essential foundation. Our Security Portal provides you with access to the information you need to validate our commitment to the security and privacy of your data.

You can easily access and download information about our comprehensive security program and posture, key compliance certifications, and how we use artificial intelligence to bring you more insight into your data.

We aim to be transparent, so you can be confident in ThoughtSpot's security and data protection practices, allowing you to focus on using AI-powered analytics to drive your organization forward.

To learn more about our security and privacy practices, visit our Trust Center at www.thoughtspot.com/trust.

Latest updates

May 12, 2026
Security Advisories
Security Advisory: Supply Chain Attack Affecting npm and PyPl Packages

Update May 13, 2026 8:30 p.m. UTC: ThoughtSpot completed its investigation and has not found any impact to ThoughtSpot products and services.

Update May 13, 2026 4:00 a.m. UTC: ThoughtSpot is still actively investigating if there is any impact of the supply chain attack on ThoughtSpot products and services.

We are aware of the supply chain attack affecting npm and PyPl packages (May 11, 2026) in which several open source packages were compromised as part of a coordinated supply chain campaign. 

Status: ThoughtSpot Cloud platform and products are not affected.

We have completed our investigation into the npm and PyPI supply chain attack. After a thorough review of our systems and dependencies, we have found no evidence of exposure or compromise. 

We will continue to monitor the situation as it develops.

Mar 24, 2026
Security Advisories
Security Advisory: Trivy, LiteLLM, and Axios Supply Chain Vulnerabilities

Update April 2, 2026: The security advisory was updated to reflect that ThoughtSpot is not impacted by the Axios supply chain compromise.

We are aware of the recent supply chain attacks affecting Aqua Security’s Trivy (March 19, 2026), the LiteLLM Python package on PyPI (March 24, 2026), and the Axios NPM package (March 30, 2026). The supply chain attacks involve potential malicious code capable of credential harvesting, data exfiltration, and lateral movement across environments.

Status: ThoughtSpot is not impacted

We have completed a thorough review of our GitHub organizations, repository dependencies, and build environments. ThoughtSpot's products, services, and infrastructure are not impacted by the incidents.

  • Trivy: No compromised Trivy versions or affected GitHub Actions were present in our environments during the impacted time windows.
  • LiteLLM: The affected LiteLLM versions (1.82.7 and 1.82.8) are not and were not used across any ThoughtSpot platform.
  • Axios: No compromised axios versions were present or used by ThoughtSpot.

No action is required from ThoughtSpot customers. Your data remains secure, and our services continue to operate normally. We maintain continuous monitoring of our supply chain dependencies and will provide updates here if our assessment changes. Your trust is paramount, and we remain committed to maintaining the security of your data. 

We will continue to update this page as new information becomes available.

If you have further questions or require a deeper technical discussion, please reach out to us.

Dec 17, 2025
Security Advisories
Security Advisory: CVE-2025-55182 - React2Shell React & Next.js CVE Disclosures

We are aware of the recently disclosed React2Shell CVE-2025-55182 vulnerability in React and Next.js. These vulnerabilities involve unauthenticated Remote Code Execution and have understandably generated significant concern across the industry.

We have completed a review of the ThoughtSpot platform environments and determined that there is no impact on our customers' data or the ThoughtSpot platform. We will continue to monitor the situation and will provide an update if our status changes.

Your trust is paramount, and ThoughtSpot is committed to maintaining the security of your data. If you have any further questions or require a deeper technical discussion, please reach out to us.

-

NIST: CVE-2025-55182