PreviewThread is in early access while we finish our data-room integrations. Book a demo →

Your data room is the most sensitive thing you'll ever hand an AI. We built for that.

Thread is designed so a PE or corporate development team can trust it with a live deal. Here is how your data is handled, isolated, and protected.

Your data is isolated

Your deals are walled off from every other customer's, enforced at the database with row-level security so one firm's data is never reachable by another.

Never used to train models

Your documents and findings are never used to train any model, yours or a provider's. Your data works for your deals only.

Encrypted end to end

Encrypted in transit and at rest. Data-room contents are processed for your deal and retained only as long as you keep the deal open.

Per-deal access controls

Role-based, per-deal permissions enforced by row-level security, so the right people see the right deals and no one else. Enterprise SSO/SAML is on the roadmap.

Sourced and traceable

Every finding traces to its document, page, and the decision made on it, so the record holds up in review. A full access log with export is on the roadmap.

You control retention

Delete a deal and its documents and derived data are removed. Your room, your timeline, your call on what stays.

Need a dedicated environment?
For larger or regulated teams, Thread runs as a single-tenant or private-cloud instance, fully isolated to your firm, with a security review to match.
Talk to us about enterprise
Principles
How we think about trust
01

The human always decides

Thread does the work and makes recommendations. It never executes a decision on its own. A person approves every consequential action, by design, not as a setting you can switch off.

02

Every finding is sourced

Nothing is asserted without provenance. Each finding traces to the document, page, and the framework or precedent behind it, so it holds up in front of an investment committee.

03

We optimize against the miss

The error that matters in diligence is the one that slips through. Cross-referencing across models exists to drive false negatives toward zero, and we measure ourselves on it.

Enterprise SSO/SAML, a full access log (who viewed what, when) with export, and SOC 2 Type II + penetration testing are on our roadmap as we move from early access to general availability. We'll publish status here and share our current posture under NDA.

Questions from your security team?

We'll walk through architecture, data handling, and our roadmap directly.