Back to Homepage
Trust & Compliance

Security & Data Protection

We prioritize the confidentiality, integrity, and availability of your scripts, voice samples, and organizational workflows.

Data Encryption

All data is encrypted in transit using Transport Layer Security (TLS 1.3) and at rest using AES-256 standards. Our database connections are secured, and critical assets (including integration API keys) are hashed and encrypted prior to persistence.

Row-Level Security (RLS)

We enforce strict PostgreSQL Row-Level Security (RLS) policies. Every query made to profiles, workspaces, project tracking pipelines, and connected publishing networks validates the user's active session, preventing cross-organization leakage.

Secure Authentication & Roles

Session handling is brokered securely using Supabase Auth. Granular Role-Based Access Control (RBAC) restricts sensitive actions (like credit purchase, workspace settings, editor assignments) strictly to authorized roles (owners and admins).

Sandbox & Compliance

Our platform code runs inside isolated sandboxes. Integration connections to HeyGen, ElevenLabs, and Submagic APIs execute programmatically via trusted servers, ensuring that individual user credentials never leak to external frontends.

Found a Security Vulnerability?

We welcome reports from security researchers and developers. If you believe you have discovered a vulnerability, please email us directly at security@thinknext.com. We will review and respond promptly.