PaperThread

Trust Centre

How PaperThread approaches security, privacy, responsible AI, data governance, access controls, infrastructure, continuity, incidents and compliance.

Trust is fundamental to PaperThread. PaperThread is an AI PeopleOps operator for lean teams. It helps organisations connect authorised workplace systems, retrieve information, prepare actions, run configured workflows and maintain a clear Thread of operational activity.

PaperThread recognises that organisations may process sensitive workplace information through the platform, including employee information, HR records, payroll-related data, documents, workflow information and operational records. Security, privacy, access control and responsible AI are therefore embedded into the design and operation of the platform.

This Trust Centre explains PaperThread's approach to security, privacy, responsible AI, data governance, access controls, infrastructure, business continuity, incident response and compliance.

Product surfaces remain Today, Ask and Thread. One operational Case maps to one Thread. PaperThread is designed to own work through to resolution, including tracked human steps, without becoming a generic chatbot, HRIS replacement, passive alerting layer or surveillance product.

1.Security

1.1Security by Design

PaperThread approaches security as a core design principle. Security considerations are incorporated throughout product design, development, deployment and operation.

PaperThread applies safeguards designed to protect the confidentiality, integrity and availability of customer information. Security is enforced on the backend. Access is denied by default. Requests are authenticated, authorised and workspace-scoped. Sensitive actions are audited.

1.2Security Principles

  • Backend-enforced authentication and authorisation
  • Deny by default; IDs alone never grant access
  • Workspace / company tenancy on every material query and mutation
  • Role-based and context-aware access (RBAC + relationship / classification checks)
  • Least-privilege connector scopes and capability checks before external actions
  • Encryption in transit and at rest for customer data and secrets
  • Secrets held in an approved vault; never sent to the frontend or to AI models
  • Append-only Thread and audit history for material activity
  • Prompt-injection and untrusted-source controls for documents and messages

1.3Security Governance

PaperThread maintains internal processes designed to support secure operation of the platform. These include security ownership, controlled access practices, confidentiality obligations, operational procedures and ongoing review of security risks.

1.4Application Security

PaperThread considers security throughout the development lifecycle. This includes secure development practices, controlled environments, review of platform changes, protection of production systems and ongoing security improvements.

1.5Technical and Organisational Measures

PaperThread maintains measures designed to protect customer information, including access controls, authentication mechanisms, permission management, monitoring, logging, vulnerability management processes, backup practices and incident response procedures. Detailed processor security measures are described in the Data Processing Addendum.

1.6Sensitive Action Controls

Sensitive workplace actions are approval-first by default. Examples include payroll changes, compensation changes, bank detail changes, contract changes, leaver actions and highly sensitive employee relations, legal or wellbeing cases.

AI may classify, retrieve, plan and draft. Deterministic services decide permission, policy/source authority, connector capability, approval, state transition, execution and verification. The model does not mutate provider or domain state directly.

1.7Thread Auditability

Material state changes append Thread events. Reminders, approvals, assignments, retries and status changes update the same Thread. Thread history is not silently rewritten; corrections are appended. Exports respect the exporting user's permissions.

1.8Connector Security

Connector calls are made from backend services. External actions require authentication, workspace validation, permission checks, capability checks and audit logging. Unknown capability fails closed. Customers remain responsible for the systems they connect and the permissions they grant.

1.9Security Responsibilities

Security is a shared responsibility. PaperThread is responsible for protecting the platform and maintaining appropriate safeguards for the Services. Customers remain responsible for managing users, permissions, connected systems, lawful instructions and lawful use of the platform.

2.Privacy and Data Protection

2.1Privacy Approach

PaperThread aligns its privacy practices primarily with UK GDPR and the Data Protection Act 2018, while considering applicable European privacy principles and internationally recognised privacy requirements.

PaperThread provides transparency around how information is processed, who controls processing decisions and how customer information is protected. GDPR is treated as a data protection programme, not a certification.

2.2Controller and Processor Model

The role of PaperThread depends on how the platform is used.

For website visitors, account administration, billing, customer support and security activities, PaperThread generally acts as a controller.

Where customers use PaperThread to process employee, contractor, candidate or workplace information, the customer determines the purposes and means of processing and acts as controller. PaperThread acts as processor where it processes Customer Personal Data on the customer's behalf. The Data Processing Addendum sets out processor terms.

2.3Data Subject Rights and Complaints

PaperThread supports data subject rights assistance for Customer Personal Data processed on a customer's behalf, and handles controller-side rights requests for PaperThread's own processing. Privacy and data protection complaints should be directed to dpo@paperthread.ai.

Global Privacy Control (GPC) is not currently recognised or supported.

3.Responsible AI

3.1AI Designed for Controlled Automation

PaperThread uses AI systems to support PeopleOps workflows, including information retrieval, classification, summarisation, drafting, workflow assistance and action preparation.

AI is designed to support human decision-making and operational efficiency rather than remove accountability. Answers are intended to be source-backed where evidence is available. Documents and messages are treated as untrusted data, not instructions.

3.2Customer-Controlled AI Authority

Customers determine the level of automation enabled through permissions, integrations, workflow settings and approval rules.

PaperThread does not independently determine its own authority or expand permissions granted by customers.

3.3What PaperThread Does Not Do

  • Does not make final employment, payroll, legal, tax, immigration, medical or wellbeing decisions
  • Does not use Customer Data / customer workspace content to train general-purpose or shared AI models
  • Does not permit AI providers to use customer data to train their models (provider no-training / data-control settings where contractually available)
  • Does not send connector secrets, bank values or unnecessary sensitive fields to AI models
  • Does not treat retrieved documents or messages as system instructions

3.4AI Limitations and Human Oversight

Like all AI systems, PaperThread may produce outputs that are incomplete, inaccurate or require additional context.

Customers remain responsible for reviewing outputs, approving sensitive actions and ensuring compliance with applicable laws. Human oversight remains required for sensitive workplace decisions.

3.5AI Data Protection

AI functionality is designed to provide requested services while maintaining customer data protection principles, purpose limitation and minimisation. Model-provider boundaries, redaction and permission checks apply before retrieval and before side effects.

4.Data Governance

4.1Customer Data Ownership

Customers retain ownership of their data. PaperThread processes customer information only as necessary to provide, secure and support the Services, and as otherwise permitted by applicable agreements.

4.2Data Processing Principles

PaperThread processes information according to customer instructions, configured permissions, authorised workflows and applicable agreements.

4.3Data Minimisation

PaperThread aims to process only information necessary to provide authorised functionality and support customer workflows. Cross-company intelligence, if offered, uses only approved aggregate projections and must not include raw policies, messages, names, emails, exact compensation or person-level data.

4.4Data Lifecycle Management

PaperThread considers the lifecycle of customer information, including collection, processing, storage, retention and deletion. Retention practices depend on data type, legal obligations, contractual requirements and operational needs.

Proposed operational defaults pending counsel confirmation:

  • Connector call logs and job runs: 90 days
  • Company people events: 30 days
  • Thread events and audit logs: 365 days

These periods are operational defaults rather than customer commitments, and retention will not remove records that are legally required to remain.

5.Access Controls

5.1Identity and Authentication

PaperThread applies access controls designed to ensure that only authorised users can access the platform. Production authentication currently uses Google Sign-In and Microsoft Sign-In.

5.2Permission Management

Customers control workspace access, user permissions, connected systems and workflow approvals. Customers are responsible for ensuring permissions remain appropriate. Access decisions for sensitive operations may consider role, relationship, case sensitivity and data classification.

5.3Least Privilege Approach

PaperThread follows principles designed to limit access based on operational requirements and authorised purposes. Finance, managers, employees and executives receive role-safe projections appropriate to their permissions.

6.Infrastructure

6.1Secure Infrastructure Design

PaperThread uses modern cloud infrastructure designed to support secure, reliable and scalable operation of the platform.

Production hosting and security providers:

  • Microsoft Azure, compute, PostgreSQL, Redis, Blob storage and Key Vault for secrets
  • Cloudflare, DNS and Tunnel

6.2Environment Management

PaperThread maintains appropriate operational practices around platform environments, updates, maintenance and service management.

6.3Monitoring and Logging

PaperThread uses operational monitoring designed to support availability management, issue detection, security investigation and troubleshooting. Logs are designed not to contain secrets or unnecessary sensitive payloads.

6.4Third-Party Technology

PaperThread relies on selected third-party technology providers to support infrastructure, authentication, payments, email, AI functionality and integrations. Confirmed categories include:

  • Authentication: Google Sign-In and Microsoft Sign-In
  • Payments: Stripe
  • Email: SendGrid
  • Integrations: Merge
  • AI providers: Gemini (primary) and OpenAI (fallback)
  • Notifications: web push where enabled

Third-party services remain subject to their own terms and privacy practices, as well as PaperThread's contractual controls.

7.Business Continuity

7.1Operational Resilience

PaperThread designs the platform with reliability and continuity in mind through monitoring, backups, recovery processes and operational procedures.

7.2Service Availability

PaperThread designs for reliable operation of core Services. Any availability target, credit or SLA commitment applies only where confirmed in the Terms of Service or an order form.

7.3Backup and Recovery

PaperThread maintains backup processes designed to support service continuity and recovery. Recovery capabilities may vary depending on circumstances.

8.Incident Response

8.1Security Incident Management

PaperThread maintains processes designed to identify, investigate, contain and respond to security incidents.

8.2Customer Communication

Where required by applicable law or contractual obligations, PaperThread will provide appropriate notifications and relevant information regarding security incidents. Security contact: [SECURITY EMAIL].

8.3Continuous Improvement

PaperThread uses operational learnings from incidents and security events to improve security practices and resilience.

9.Compliance

9.1Legal and Regulatory Alignment

PaperThread aligns its practices with applicable privacy and security obligations, including UK GDPR, the Data Protection Act 2018 and relevant international privacy principles.

PaperThread operates a UK/EU GDPR data protection programme, with DPA availability, data subject rights support, subprocessor transparency, transfer safeguards and a data protection complaints process. GDPR is not a certification.

9.2Assurance and Certification Status

PaperThread does not claim SOC 2 or ISO 27001 certification. Certification evidence is in final review, and certification details will be published only once verified.

9.3Governance Framework

PaperThread maintains governance practices covering privacy, security, AI usage, data handling and operational processes.

9.4Enterprise Assurance

PaperThread supports customer due diligence through transparency around security practices, privacy approach, AI governance, subprocessors and data handling processes. Detailed materials may be provided under NDA where appropriate.

10.Related Trust and Legal Pages

This Trust Centre should be read together with:

  • Security
  • Privacy Policy
  • Terms of Service
  • Data Processing Addendum (available on request)
  • Cookie Policy
  • Subprocessors (available on request)
  • AI Clarity Statement
  • Contact

Contact points for public enquiries:

  • General: hello@paperthread.ai
  • Sales: sales@paperthread.ai
  • Privacy: dpo@paperthread.ai
  • Security: [SECURITY EMAIL]
  • Legal: legal@paperthread.ai
  • Data protection complaints: dpo@paperthread.ai

Last updated: 31 July 2026