Trust Center

Trust Center

Last reviewed: September 4, 2026

This page describes, in specific and honest terms, how Think4Ei approaches security, privacy, AI governance, and independent assurance. We deliberately avoid absolute claims like "100% secure" or "zero risk" — no real system can honestly make those guarantees. Instead, every item below is labeled with one of four statuses, consistently applied:

Implemented & internally verified Independently assessed In progress Planned

"Implemented & internally verified" means our own engineering team has built the control and confirmed it works against real, live checks. It is not the same as an independent third-party audit — where we have one of those, we say "Independently assessed" instead, and today we do not yet have a completed independent security audit (see Assurance Status below).

Security overview

ControlStatusWhat it means in practice
Encryption in transit Implemented Traffic to think4ei.com and the platform is served over HTTPS/TLS.
Encryption at rest Planned Full disk-level encryption for all underlying storage volumes is a tracked, planned improvement — it is not yet complete across every volume today, and we're not going to claim otherwise.
Tenant isolation In progress The platform enforces tenant-scoped, fail-closed access checks by design across its systems. We run a dedicated, ongoing tenant-isolation hardening program that actively scans for and closes gaps as part of routine operations — this is real, continuous work, not a one-time pass we consider finished.
Role-based access control (RBAC) Implemented Elevated or sensitive actions (approvals, role changes, financial holds, and similar) are gated by server-computed permission checks tied to a verified session, not a client-side toggle.
Audit logging Implemented Sensitive actions across the platform write to an audit log used for traceability and incident investigation.
Document/record integrity sealing Implemented Ingested documents and records are cryptographically sealed (merkle-hashed) at intake by our internal "Sentinel" mechanism, so tampering with a sealed record after the fact is detectable.
Vulnerability & penetration testing Planned A focused third-party penetration test is planned alongside our formal audit engagement (see Assurance Status). We have not yet had one completed by an outside firm.

Privacy & data governance

Our approach to privacy is described in full at the Privacy Policy and, for client platform data, the Data Processing Agreement. A few specific, verifiable practices:

AI governance

Assurance status

We do not hold SOC 2, ISO 27001, FedRAMP, or any other completed independent security certification today. Any statement elsewhere that could be read to imply otherwise is wrong and should be reported to support@think4ei.com so we can correct it.

When any of the above moves from Planned to Independently assessed, this page — and only this page's real, dated status — is what we'll point to as evidence. We will not describe a "Planned" item as complete anywhere else on the site.

Security reporting

Found a security issue? We want to know. See our Security Reporting policy for scope and how to report responsibly.

Questions

Email support@think4ei.com or sales@think4ei.com for anything not covered here, including vendor-security questionnaires.