Trust & Security

Security at Thorero

Thorero is built for organisations where operational governance cannot fail. This page describes our security posture, our current capabilities, and our roadmap. We describe what exists today — not what is planned.

Last updated: 29 September 2026

Our principles

Honest by default

We describe what we have. Where a capability is on the roadmap, we say so.

Least privilege

Users see only what their role, department, and location scope permit.

Evidence-based governance

Every state change, approval, and closure is logged. Nothing relies on memory.

Server-enforced controls

Critical permissions are enforced on the server, not just hidden in the browser.

Where your data lives

All customer data is stored in Supabase — a managed PostgreSQL platform hosted in data centres in the United States and the European Union. Supabase is SOC 2 Type II certified and ISO 27001 certified.

The Thorero web application is served through Vercel, a global content delivery network. Vercel does not store your operational data — it delivers the frontend only. Vercel is SOC 2 Type II compliant.

When the AI Copilot is used, a compressed summary of your question and the relevant scoped context is transmitted to Groq for processing. Only aggregate counts and summaries are sent — never full operational records. You may disable the AI Copilot at any time from within the Copilot panel.

Access control

Thorero enforces access control at three levels:

  • Authentication

    Email and password with secure session management. Google sign-in is supported. Multi-factor authentication is planned.

  • Role and department scope

    Users are assigned to a role, department, and unit. Each combination determines which modules they can access. This is enforced on the server, not just hidden in the interface.

  • Location scope

    Every record is tied to a location. A user's role and location scope determine which sites they can see across every module. Location filters are applied at the database level.

Data protection

  • All data is encrypted in transit using TLS 1.2 or higher.
  • All data is encrypted at rest by the underlying infrastructure.
  • Passwords are hashed and never stored in plain text.
  • Access to production systems is restricted to named personnel.

Audit and monitoring

  • Every record change creates an audit trail entry with the user, timestamp, and action taken.
  • Every governance action — approval, escalation, or closure — is logged to an immutable trail.
  • Every AI Copilot question is logged with the query text and timestamp.
  • Server-side access to the database is logged by Supabase.

Availability and backup

  • The platform runs on managed infrastructure with automatic failover.
  • Customer data is backed up automatically by Supabase.
  • Target uptime during the pilot period is 99.5%.
  • Planned maintenance is scheduled outside Nigerian business hours where possible.

Compliance

Thorero is compliant with the Nigeria Data Protection Act 2023 (NDPA). We process personal data in accordance with the NDPA, and we have a Data Processing Agreement available for all customers.

We are pursuing SOC 2 Type I certification as part of our commitment to enterprise-grade security. This certification is not yet complete. We will publish the certificate on this page as soon as it is issued.

Roadmap — capabilities in progress

We list the following capabilities because we believe in honesty. Each is on our roadmap.

  • Row-Level Security (RLS)

    Fine-grained database-level security policies scoped to individual tenants. In development.

  • Multi-factor authentication (MFA)

    Time-based one-time passwords and hardware key support for all users. Planned.

  • Single Sign-On (SSO)

    SAML and OIDC integration for enterprise identity providers such as Microsoft Entra ID and Google Workspace. Planned.

  • SOC 2 Type I certification

    Independent audit and certification of security controls. Planned.

  • Uptime and error monitoring

    Real-time uptime monitoring, error tracking, and a public status page. In development.

Incident response

In the event of a security incident affecting customer data, we will:

  1. 1Notify affected customers without undue delay, and in any event within 72 hours of becoming aware of the incident.
  2. 2Provide a description of the incident, its scope, and the categories of data affected.
  3. 3Describe the remediation measures taken or planned.
  4. 4Cooperate fully with the customer's own incident response process.

Reporting a security concern

If you believe you have identified a security vulnerability in Thorero, please contact us directly. We take every report seriously and will respond within two business days.

Security contact

security@thorero.com

Please do not publicly disclose security issues before we have had a chance to investigate and respond.

Related documents

Thorero — Operational Governance Platform

A product of Two Stone Nig Ltd (RC 1405761)

Questions about this page: security@thorero.com