How it works
Six controls that protect your data
Each one is a control in the product today, not a roadmap item — the full statement documents them in detail.
Encrypted at every layer
All traffic uses TLS 1.3. The database, backups and document storage are encrypted at rest with AES-256. Bank details and other sensitive fields are restricted further, and every reveal is logged — not just who changed the record, but who viewed it.
Access is tied to identity and role
Recruiters, credentialing, coordinators, finance and admins each receive a defined permission set. Providers and facility contacts see only their own records. Roles are stored separately from profiles so they cannot be self-edited or escalated.
Multi-factor authentication on sensitive roles
Administrators and finance users verify with an authenticator app or an emailed one-time code. Passwords are screened against known breach lists, and idle sessions close automatically after 30 minutes.
An audit trail you can actually read
Logins, role changes, credential updates, banking reveals, exports and imports are written to an immutable audit log with who, what and when. The log is visible inside the product, not hidden in a backend only we can query.
Resilient, certified infrastructure
Thotara runs on cloud providers that hold their own SOC 2 and ISO 27001 certifications for data centres, physical security and network layers. We operate no server room, and no customer data is stored on employee laptops.
Continuous security monitoring
Dependencies are scanned for known vulnerabilities, changes go through reviewed change control, and public endpoints use constant-time secret verification. Security is part of every deployment, not a one-time checklist.
Compliance
What SOC 2 and ISO 27001 actually mean here
Plain explanations of the frameworks, plus exactly where Thotara stands against each.
SOC 2 Type II
SOC 2 examines whether the controls a vendor claims actually operated over a period of months, across security, availability and confidentiality. Thotara is built to those Trust Services Criteria: documented access control, change management, monitoring, incident response, vendor review and evidence capture. We are progressing through readiness toward a Type II examination and share our current status and evidence during security review.
ISO/IEC 27001:2022
ISO 27001 is the international standard for running an information security management system. Thotara's controls are mapped to Annex A themes — organizational, people, physical and technological — and section 17 of our full security statement shows that mapping control by control, so your assessor can trace each requirement to something concrete in the product.
Certified cloud infrastructure
Thotara runs on major cloud providers that hold their own SOC 2 and ISO 27001 certifications for the data centres, physical security and network layer. We operate no server room of our own, and no customer data is stored on employee laptops.
At a glance
The numbers your assessor will ask for
- AES-256
- Encryption at rest for database, files and backups
- TLS 1.3
- Encryption in transit for every request
- 35 days
- Encrypted backup and point-in-time recovery window
Operating practices
- Named individual accounts — no shared logins anywhere
- Least-privilege access granted at onboarding and removed at offboarding
- Admin-run access reviews with inactivity flags and exportable evidence
- Server-side validation on every write, with no privileged key in the browser
- Dependency and vulnerability scanning with reviewed change control
- Encrypted backups with point-in-time recovery
- Constant-time secret verification on public webhook and scheduled endpoints
- A recurring in-app compliance checklist that records who reviewed what, when
Questions
Security questions, answered directly
How is our data encrypted?
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. That includes the database, file storage and backups. Sensitive fields such as bank account details are additionally restricted and logged every time they are revealed.
Who can access our data?
Only named users inside your organization with an assigned role. Access is enforced by the database using verified identity and membership, not by application filters that a bug could bypass. Our own staff cannot browse customer workspaces.
What happens if there is a security incident?
We have an incident response plan with defined roles, containment steps, notification timelines and evidence preservation. Customers with active agreements are notified without unreasonable delay when their data is affected.
Do you have a SOC 2 report we can read today?
We share our current readiness status, control documentation and completed security questionnaires under NDA during review, and will provide the Type II report once the examination period closes.
How do we complete our vendor security questionnaire?
Send it to security@thotara.com before your call. The full security statement answers most questions directly, and we return written responses rather than pointing you at marketing copy.
What happens to our data if we leave?
You can export your records and documents during a 30-day window after termination, after which the workspace is permanently deleted. Signed letters and agreements stay immutable for as long as the subscription runs.
How do we report a vulnerability?
Email security@thotara.com with reproduction detail. We acknowledge promptly, work the issue with you, and do not pursue good-faith researchers who follow our coordinated disclosure guidance.

