Skip to main content
Trust & Security

Security at FactoryThread

FactoryThread is a data virtualization platform — not a system of record for customer business data. Records flow through our workers in memory and land in your target system. The application database holds only operational metadata.

The core claim

FactoryThread is not designed to be a system of record for customer business data. The application database holds only the operational metadata required to run, secure, and troubleshoot the service — plus two narrow, documented exceptions on the failure path.

  • Caveat 1 — Error samples

    On flow execution errors, a small sample of the failing record(s) is persisted into the insights message column for debugging. Successful executions store only metadata (status, duration, counts).

  • Caveat 2 — Worker staging

    The worker may use ephemeral in-memory or temporary staging for certain operations during execution. This staging is not persisted across runs.

What we store

What lives in our database — and what doesn't

We persist

  • Connection credentials and metadata
  • Flow, view, and API definitions
  • Workspace, user, API-key, and billing metadata
  • Execution insights — status, duration, node counts, error messages
  • Small input samples on execution errors (for debugging)

We do not persist

  • Customer business records flowing through pipelines
  • Successful execution outputs
  • Preview results — held in memory only
  • Ephemeral worker staging — discarded across runs
Compliance readiness

Aligned controls. Target audits in 12-24 months.

We do not currently hold formal certifications. The frameworks below describe our control alignment today and our planned audit timeline.

See the Compliance Readiness Statement for current alignment, gaps, and target audit timelines per framework.

Disclosed gaps

What we're shipping next

We disclose what's in flight rather than wait to be asked. These four items are on our near-term roadmap.

ItemDetailTarget
Connection metadata encryption at restAES-256-GCM with envelope keys for credentials in connection_data.metadata.Q2 2026
Strict TLS verification by defaultPer-connection self-signed cert opt-in; reject by default for outbound connectors.Q2 2026
Tenant-scoped activity audit logComprehensive who-did-what-when across user actions, beyond publish and API key events today.Q3 2026
Flow change history with diff viewerRetain prior versions of flow definitions; surface diffs alongside the editor.Q3 2026

Need a CAIQ-Lite, SIG-Lite, or custom questionnaire?

We complete vendor security questionnaires for prospects and customers. We typically turn around requests within one business day.

Contact support@factorythread.com