Security at Common Thread

Commercial confidence.
Built on protection.

Commercial information demands considered protection. Encryption, controlled access and independently audited infrastructure underpin our approach.

Security overview · Updated 22 September 2026

01 / Encryption in transit

Encrypted in transit

HTTPS and TLS encrypt connections to our website, helping protect information as it travels between your browser and our hosting infrastructure.

HTTPS / TLS

02 / Encryption at rest

Encrypted at rest

Our database provider uses AES-256 encryption to protect stored data. This infrastructure protection works alongside the application’s access controls.

AES-256 database encryption

03 / Access controls

Controlled by role

Workspace membership and role-based permissions govern access to organisation data and administrative actions. These controls are enforced by the application when requests are made.

Organisation access · Administrative permissions

Independent assurance

Standards behind
the infrastructure.

Our infrastructure providers undergo independent assessment of their security controls and information security management.

Provider assurance

SOC 2 Type II

Independent assessment of provider security controls over time.

Provider certification

ISO 27001

An internationally recognised standard for information security management.

Credentials cover our providers’ audited services. Common Thread does not hold these certifications itself. Scope and supporting documentation can be discussed during due diligence.

Security due diligence

Confidence for
your review.

Evaluating Common Thread for your agency? Speak to our team about your security requirements and supplier review.

Discuss security

To report a security concern, contact the same team. Please omit credentials and customer data.