Skip to content

Security policy

Standard Thinking uses layered safeguards designed to protect the confidentiality, integrity, and availability of customer workloads. Security is a shared responsibility between our platform and each customer deployment.

1. Data protection

  • Network traffic to supported endpoints is encrypted in transit using current transport security protocols.
  • Stored customer and account data is encrypted at rest where appropriate to the storage system and risk.
  • Customer Content is processed under the retention and caching terms applicable to the service and configuration. ZDR commitments apply where expressly identified; customer-enabled storage follows its separate retention terms. See the Data Processing Policy, §4.
  • Content-free service metadata may be retained for metering, billing, security, reliability, and platform operations. Customer Content remains subject to the purpose and retention limits in the Data Processing Policy.
  • Customer Content is not used to train public or shared models unless the customer gives a separate, explicit opt-in or that use is expressly permitted under Section 5.3 of the Terms of Service.
  • Subprocessors are required to follow the processing and retention restrictions applicable to the service, including materially equivalent ZDR restrictions where a ZDR commitment applies.

2. Identity and access

We design access to production systems around least privilege, separation of duties, and authenticated administrative access. Access to sensitive systems is limited to personnel and services with a business need and is reviewed as roles change. Administrative and customer account activity may be logged for security and audit purposes.

Project-scoped credentials and revocation controls help customers limit the effect of a compromised key. Enterprise configurations may add organization controls, single sign-on, private networking, dedicated capacity, or other safeguards described in an order.

3. Operational security

Our operational program is designed to include secure configuration, change control, dependency and vulnerability management, environment separation, backup and recovery planning, and monitoring for suspicious behavior. We evaluate reported vulnerabilities and prioritize remediation based on exploitability and potential impact.

We use infrastructure and model partners to provide portions of the Services. We assess vendors based on the nature of the service and data involved and use contractual and technical controls appropriate to the risk.

4. Incident response

We maintain procedures designed to identify, contain, investigate, remediate, and learn from security incidents. If an incident affects customer data, we will notify affected customers as required by applicable law and contractual commitments, and we will provide information reasonably available to support their response.

Service availability events are communicated through our status page when appropriate.

5. Customer responsibilities

Customers must:

  • protect account credentials and API keys, limit access, rotate secrets, and avoid embedding secrets in public client code;
  • configure applications, networks, permissions, and data retention according to their risk and legal obligations;
  • validate Output before using it in production or a consequential decision;
  • avoid sending regulated or highly sensitive data unless a written agreement permits it;
  • monitor for unauthorized activity and promptly disable compromised credentials; and
  • keep integrations and dependencies current and follow our documentation and usage limits.

6. Reporting a vulnerability

If you believe you found a security vulnerability, email contact@standardthinking.ai with a concise description, affected endpoint or feature, reproduction steps, and potential impact. Do not access data that is not yours, disrupt production, use social engineering, or publicly disclose an unresolved issue.

We will acknowledge legitimate reports and coordinate remediation and disclosure as appropriate. This policy does not create a bug bounty or promise payment.

7. Scope and updates

This page is a public overview and does not replace a signed security exhibit, data processing addendum, or enterprise order. Safeguards evolve with the Services and threat landscape, so we may update this policy as our program changes.

All policies · Contact us about this policy