Trust & Security
Security at Thorero
Thorero is built for organisations where operational governance cannot fail. This page describes our security posture, our current capabilities, and our roadmap. We describe what exists today — not what is planned.
Last updated: 29 September 2026
Our principles
Honest by default
We describe what we have. Where a capability is on the roadmap, we say so.
Least privilege
Users see only what their role, department, and location scope permit.
Evidence-based governance
Every state change, approval, and closure is logged. Nothing relies on memory.
Server-enforced controls
Critical permissions are enforced on the server, not just hidden in the browser.
Where your data lives
All customer data is stored in Supabase — a managed PostgreSQL platform hosted in data centres in the United States and the European Union. Supabase is SOC 2 Type II certified and ISO 27001 certified.
The Thorero web application is served through Vercel, a global content delivery network. Vercel does not store your operational data — it delivers the frontend only. Vercel is SOC 2 Type II compliant.
When the AI Copilot is used, a compressed summary of your question and the relevant scoped context is transmitted to Groq for processing. Only aggregate counts and summaries are sent — never full operational records. You may disable the AI Copilot at any time from within the Copilot panel.
Access control
Thorero enforces access control at three levels:
Authentication
Email and password with secure session management. Google sign-in is supported. Multi-factor authentication is planned.
Role and department scope
Users are assigned to a role, department, and unit. Each combination determines which modules they can access. This is enforced on the server, not just hidden in the interface.
Location scope
Every record is tied to a location. A user's role and location scope determine which sites they can see across every module. Location filters are applied at the database level.
Data protection
- All data is encrypted in transit using TLS 1.2 or higher.
- All data is encrypted at rest by the underlying infrastructure.
- Passwords are hashed and never stored in plain text.
- Access to production systems is restricted to named personnel.
Audit and monitoring
- Every record change creates an audit trail entry with the user, timestamp, and action taken.
- Every governance action — approval, escalation, or closure — is logged to an immutable trail.
- Every AI Copilot question is logged with the query text and timestamp.
- Server-side access to the database is logged by Supabase.
Availability and backup
- The platform runs on managed infrastructure with automatic failover.
- Customer data is backed up automatically by Supabase.
- Target uptime during the pilot period is 99.5%.
- Planned maintenance is scheduled outside Nigerian business hours where possible.
Compliance
Thorero is compliant with the Nigeria Data Protection Act 2023 (NDPA). We process personal data in accordance with the NDPA, and we have a Data Processing Agreement available for all customers.
We are pursuing SOC 2 Type I certification as part of our commitment to enterprise-grade security. This certification is not yet complete. We will publish the certificate on this page as soon as it is issued.
Roadmap — capabilities in progress
We list the following capabilities because we believe in honesty. Each is on our roadmap.
Row-Level Security (RLS)
Fine-grained database-level security policies scoped to individual tenants. In development.
Multi-factor authentication (MFA)
Time-based one-time passwords and hardware key support for all users. Planned.
Single Sign-On (SSO)
SAML and OIDC integration for enterprise identity providers such as Microsoft Entra ID and Google Workspace. Planned.
SOC 2 Type I certification
Independent audit and certification of security controls. Planned.
Uptime and error monitoring
Real-time uptime monitoring, error tracking, and a public status page. In development.
Incident response
In the event of a security incident affecting customer data, we will:
- 1Notify affected customers without undue delay, and in any event within 72 hours of becoming aware of the incident.
- 2Provide a description of the incident, its scope, and the categories of data affected.
- 3Describe the remediation measures taken or planned.
- 4Cooperate fully with the customer's own incident response process.
Reporting a security concern
If you believe you have identified a security vulnerability in Thorero, please contact us directly. We take every report seriously and will respond within two business days.
Security contact
Please do not publicly disclose security issues before we have had a chance to investigate and respond.
Related documents
- Privacy Policy — how we collect, use, and protect your information
- Terms of Service — the terms governing your use of Thorero
- Data Processing Agreement — available on request
- Sub-processor List — available on request
Thorero — Operational Governance Platform
A product of Two Stone Nig Ltd (RC 1405761)
Questions about this page: security@thorero.com