Do you have SOC 2?
No. Thermal does not currently hold SOC 2, ISO 27001, HIPAA, or PCI DSS certification, and we don't claim any of them. This page describes the controls we've actually built, not a pending audit or a roadmap promise.
- Row-level security, not app logicA database session scoped to one organization cannot read or write another organization's rows. Postgres enforces it, independent of the application code doing the querying. Live
- Append-only event ledgerCreates, status changes, completions and deletes on customers, sites, equipment, agreements, work orders and invoices each write an event in the same transaction as the change. The event commits only if the change does. Live
- Org-wide audit log and exportAn owner can browse the full event history filtered by actor, action, entity, branch and date, and export it as CSV or JSON from Settings. Live
This is one of six questions answered individually. The full picture — access control, audit trail, data handling, integrations, and what we haven't built — is on the security page.
02
The other five.
Each one is its own page, so you can forward the single answer somebody asked for.
03
Still not satisfied?
Fair. Bring the question to a call and we'll show you the control running against real records, not a slide about it.