Security & Compliance
Effective September 27, 2026
Account protection
Thrive uses Supabase authentication and server-side checks for protected account operations. Administrative access is restricted to configured, verified accounts. Keep passwords unique and protect the email account used for sign-in.
Data access
Account APIs restrict private profile access to the signed-in owner. Documents submitted through the upload API require authentication, are limited in size and file type, and receive temporary access URLs. Infrastructure settings and database permissions require ongoing review.
Responsible disclosure
If you discover a possible vulnerability, email contact@usethrive.xyz with the affected URL, steps to reproduce, and impact. Avoid accessing other people?s data, disrupting service, or publishing private information. Do not include passwords or access tokens in reports.
Compliance statements
This page describes application safeguards; it does not assert SOC 2 certification, ISO certification, or universal regulatory compliance. Specific contractual requirements and applicable privacy obligations must be evaluated separately.
Your role
Review external application destinations, avoid sharing credentials with recruiters, and report suspected account compromise promptly. Security measures reduce risk but cannot guarantee that every incident will be prevented.