Company logo| Trust Center

Thoughtful Oasis

Thoughtful Oasis is an AI research lab in Enschede, the Netherlands, building interpretable systems for mission-critical work in government and industry, operating under an ISO/IEC 27001:2022-certified information security management system.

Compliance

Industry standards and compliance frameworks this organization is aligned with or currently certified against.

GDPR:2020

Resources

Downloadable security policies, compliance reports, and certificates. Some documents may require an access request.

Security Documentation

Statement of Applicability (SOA) - ISO27001:2022 - 2025

Our Statement of Applicability for ISO27001:2022

Controls

Specific security measures this organization has implemented, alongside their current operational status.

Subprocessors

Third parties this organization works with that may process customer data.

Attio CRM & Sales
UK

CRM used for sales pipeline and contact management.

Cursor AI & Machine Learning
US

AI-augmented code editor used by the engineering team.

Anthropic AI & Machine Learning
US

Claude API used for AI-assisted development and internal automation.

Valley CRM & Sales
US

LinkedIn outreach automation used for sales prospecting.

Amazon Web Services S3 Cloud Infrastructure
US

Object storage used for file storage across our applications.

Frequently Asked Questions

Answers to commonly asked questions regarding this organization's security and privacy practices.

Access & Authentication

How is internal access to systems and customer data authenticated?

Staff sign in through a single Google Workspace identity, with single sign-on enabled wherever a system supports it. Multi-factor authentication is required for all administrative and production access.

Data Protection & Encryption

How are backups handled?

The primary database is backed up daily, using the platforms' native backup and versioning rather than bespoke pipelines. Backups are verified and disaster recovery is tested periodically.

Is my data encrypted?

Yes, data is encrypted in transit with Transport Layer Security and at rest by the managed platforms that store it, such as Heroku Postgres. All employee devices use full-disk encryption.

How are secrets and credentials managed?

Application secrets are held in Heroku config vars, GitHub Actions secrets, or LastPass, never hard-coded. Code reviews check for hard-coded secrets, and any secret accidentally committed is rotated immediately.

Hosting & Data Residency

Where is your service hosted and where is customer data stored?

Our primary data stores sit in EU regions: Heroku's EU data plane, AWS in Luxembourg and Ireland, background compute on Hetzner in Germany, and the vector database in the Netherlands. Some platform administration and subprocessors are US-based, covered by EU adequacy decisions or Standard Contractual Clauses.

Is customer data processed outside the EU?

The primary data plane sits in EU regions. A number of subprocessors, for example source-code hosting and some AI model providers, are US-based, with transfers covered by EU adequacy decisions where available and otherwise by Standard Contractual Clauses; the full list is in the Subprocessors section.

Privacy & GDPR

Are you GDPR compliant?

Yes, we process personal data in line with the GDPR and our Privacy Policy. We act as a data processor, with the customer as controller.

Secure Development & Vulnerability Management

How do you manage vulnerabilities?

Dependencies, source code, and secrets are scanned continuously with Dependabot, GitHub CodeQL, and secret-scanning across all active repositories. We monitor vendor and community advisories, and track runtime errors in Sentry.

Powered by