Last updated: October 2, 2026
This page describes the security practices Thrifty AI applies to its website and to its services, including Thrifty Studio, the Thrifty AI APIs and SDKs, managed deployments and Thrifty Agent (together, the "Services"). Artificial humans process sensitive content, including voice audio, camera video frames, facial imagery, screen-share content, conversation recordings and transcripts, and interview and assessment results. We design our security program with that in mind.
This page is a general overview. The specific security commitments that apply to a customer are set out in that customer's agreement with us, including our Platform agreement and Data processing agreement. For additional information, visit our Trust Center.
1. Security program
We maintain administrative, technical, physical, and organizational security measures designed to protect the data customers and end users share with us against unauthorized access, loss, alteration and disclosure. We review these measures periodically and update them as our Services, the threat landscape and applicable laws change.
2. Infrastructure security
- The Services are hosted with established cloud infrastructure providers that maintain physical, environmental and network security controls for their data centers. Our current subprocessors are listed on our Subprocessors page.
- Production environments are logically separated from development and testing environments, and customer data is provisioned in isolated production environments.
- Network access to production systems is restricted using firewalls, network segmentation and other controls, and administrative access is limited to authorized personnel.
- We apply security updates to systems and dependencies on a risk-prioritized basis and monitor production systems for availability and suspicious activity.
- Real-time media streams between end users and artificial humans are routed through infrastructure we control or through contracted subprocessors, and are not shared with other customers.
3. Encryption
- Data in transit between end users, customer applications and the Services, including real-time voice and video streams, is encrypted using industry-standard transport encryption.
- Data at rest, including recordings, transcripts, uploaded knowledge-base documents and account data, is encrypted using industry-standard encryption.
- Encryption keys and credentials are managed with restricted access and are not stored alongside the data they protect.
4. Access control
- Access to customer data by Thrifty AI personnel is restricted and granted only where required for a person's job function, such as providing support at the customer's request or maintaining the Services. Access requires approval and follows the principle of least privilege.
- Access to our internal administration tools is logged, and access logs and permissions are reviewed periodically.
- Data is associated with customer identifiers so that one customer's data is not accessible to another. Within a customer account with multiple workspaces or teams, data from one workspace is not accessible to another unless the customer configures it to be.
- Thrifty Studio supports role-based permissions so that customers can control who can create, edit, publish and review artificial humans, knowledge bases, recordings and reports. Where available on a customer's plan, the Services support single sign-on and multi-factor authentication.
- API access is authenticated with keys that customers can create, rotate and revoke. Customers are responsible for keeping their keys confidential and for not embedding secret keys in client-side code.
- Personnel with access to customer data are bound by confidentiality obligations and receive security and privacy training.
5. Handling of recordings, video and voice
Artificial humans can process voice audio, camera frames, facial imagery, screen-share content and recordings. We apply the following practices to this content:
- Camera frames and screen-share content are processed to let the artificial human see and respond during a conversation. Unless recording is enabled, they are not retained after the conversation beyond what is needed to operate and secure the Services.
- Conversation recordings, including those produced for AI interviews, assessments and roleplays, are created only where the customer has enabled recording. Customers are responsible for informing end users and obtaining any consent required before recording.
- The Services are not designed to identify end users from their face or voice. Where a customer creates an artificial human from a real person's likeness or voice, the source material is used only to create and operate that customer's artificial human.
- Access to recordings, transcripts and scored reports within a customer account is governed by the customer's role-based permissions.
6. Data retention and deletion
- We retain customer data only for as long as needed to provide the Services, to meet our legal obligations, or as otherwise set out in the customer's agreement.
- Customers can configure retention periods for recordings, transcripts and conversation memory, and can delete individual recordings, transcripts and knowledge-base documents at any time.
- When a customer deletes data or closes its account, we delete or de-identify that data from active systems within the period set out in the customer's agreement. Copies in backups are deleted in the ordinary course of backup rotation.
- All data, files and other materials that customers make available to Thrifty AI, along with conversation inputs and generated outputs, are owned by the customer as set out in the customer's agreement.
7. Model and data usage
We do not use customer data, including recordings, transcripts, voice audio, camera video, uploaded documents, inputs or outputs, to train or improve models shared with other customers without the customer's permission. Where a customer asks us to tune an artificial human using its own data, that tuning is used only for that customer.
We take measures to reduce bias and harmful content in artificial human conversations, including safety filters on inputs and outputs, guardrails that customers can configure, human review of our systems before release, and a feedback loop for reporting problems. We will provide further documentation about these measures on customer request.
8. Application security and prompt injection
- We follow secure development practices, including code review and testing of changes before they are deployed to production.
- We take measures to mitigate prompt injection and related attacks, including separating system instructions from user and knowledge-base content and limiting the actions an artificial human can take on connected systems to those the customer has configured.
- Content that end users show to the artificial human through the camera or screen share is treated as untrusted input.
9. Vulnerability disclosure
We welcome reports from security researchers. If you believe you have found a security vulnerability in the Services or our website, please report it to security@thriftyai.com with enough detail for us to reproduce the issue. We ask that you act in good faith: do not access, modify or delete data belonging to others, do not degrade the Services for other users, do not use social engineering or physical attacks, and give us a reasonable opportunity to fix the issue before disclosing it publicly. We will acknowledge valid reports and keep you informed of our progress.
10. Incident response
We maintain incident response procedures for identifying, containing, investigating and remediating security incidents. If we become aware of a security incident that affects a customer's personal data, we will notify the affected customer without undue delay and in accordance with our Data processing agreement and applicable law, and we will provide information the customer reasonably needs to meet its own obligations.
11. Privacy and AI regulation
We are committed to meeting our obligations under the privacy and data protection laws that apply to us. Read our Privacy policy and Data processing agreement to learn how we handle personal data, and our approach to global AI regulation for information on the EU AI Act and other AI laws.
12. Contact
Please contact security@thriftyai.com with questions about security at Thrifty AI, or to discuss your organization's specific security requirements. For questions about our trust practices more generally, contact trust@thriftyai.com or visit our Trust Center.