Back to Thrive

Security & Compliance

Effective September 27, 2026

Account protection

Thrive uses Supabase authentication and server-side checks for protected account operations. Administrative access is restricted to configured, verified accounts. Keep passwords unique and protect the email account used for sign-in.

Data access

Account APIs restrict private profile access to the signed-in owner. Documents submitted through the upload API require authentication, are limited in size and file type, and receive temporary access URLs. Infrastructure settings and database permissions require ongoing review.

Responsible disclosure

If you discover a possible vulnerability, email contact@usethrive.xyz with the affected URL, steps to reproduce, and impact. Avoid accessing other people?s data, disrupting service, or publishing private information. Do not include passwords or access tokens in reports.

Compliance statements

This page describes application safeguards; it does not assert SOC 2 certification, ISO certification, or universal regulatory compliance. Specific contractual requirements and applicable privacy obligations must be evaluated separately.

Your role

Review external application destinations, avoid sharing credentials with recruiters, and report suspected account compromise promptly. Security measures reduce risk but cannot guarantee that every incident will be prevented.