How Secure Is Thicket?

Where Thicket stores your data, how it protects connections and accounts, who can see your work, and how to report a security concern.

Thicket is built and run by Vesperion Gate Inc., which publishes where your data lives and how it's protected on its Trust and security page. Here's a summary, along with the security settings you control.

Where your data lives

  • Thicket and its database run on dedicated infrastructure in Ashburn, Virginia, in the United States.
  • Uploaded files are stored in Cloudflare R2 in the United States, encrypted at rest.
  • Automated daily backups are stored separately, also in the United States.

How connections and sign-ins are protected

  • Every connection to Thicket uses HTTPS.
  • Passwords are stored only as one-way hashes, never as readable text.
  • Two-factor authentication is available to everyone, and account owners can require it for everyone except clients at Admin > Security: require 2FA. See Two-Factor Authentication.
  • Changing your password signs you out on every other device.
  • When the email address on a confirmed account changes, Thicket sends a notice to the old address.
  • Card payments go through Stripe's checkout, so you enter card details on Stripe's pages, not in Thicket.

How accounts are kept apart

Each Thicket account's data is separated in the database with PostgreSQL row-level security. It works alongside the permission checks Thicket makes on every request, as a second layer.

Who can see your work

Inside your account, access follows the people and projects you set up:

  • Your team sees a project when they've been added to it, or when the project is open to the whole team.
  • Clients see only the projects they've been added to, and only the items shared with clients. See What Clients Can See and Do.
  • An item has no public link until someone on your account creates one. Owners can review every public link, and unpublish any of them, at Admin > Manage public items. See Sharing Items with Public Links.

Apps and AI tools you connect

API tokens and apps you connect, including AI assistants that use Thicket's MCP connector, work as you and reach only what you can reach. Content they read is handled under that tool's own terms and settings, and read-only access still shares your data with the tool. You can revoke any of them in My settings: see Connected Apps and Access Tokens.

Vesperion Gate doesn't use private Thicket customer content to train general-purpose AI models.

Access by Vesperion Gate

Vesperion Gate accesses account content when it's needed to provide the service, answer a support request, protect the service, or meet a legal obligation. Administrative access to its servers uses keys over a private network, and password login to the servers is turned off. Cloudflare sits in front of public traffic, and firewalls deny any connection that hasn't been explicitly allowed.

When you cancel

A cancelled account can be restored for 30 days. After that, its content is scheduled for removal. Backups of customer content are kept for at most 28 days, and copies are scheduled for deletion within 60 days of closing the account. See Cancelling Your Account.

Privacy

Vesperion Gate doesn't sell personal information. For retention details and your rights, read the Privacy Policy. The provider register lists the services involved in running Thicket, and the Data Processing Addendum covers customers who need one.

Report a security concern

If you think you've found a security issue in Thicket, email security@vesperiongate.com.

If you think someone else has used your account, change your password in My settings > Manage sign-in security, which signs you out everywhere else, and contact support.

Was this article helpful?