← THROUGHLINE Log in →

Last updated: August 2026

This page describes how ThroughLine handles data today. We're an early-stage product, and we'd rather be precise about where we are than vague or overstated — this document will evolve as our infrastructure and compliance posture do.

What ThroughLine stores

ThroughLine is a workflow registry — it tracks the structure, stages, and history of process workflows. It is not a document management system or loan origination system, and it is not designed to store loan-level personally identifiable information (PII) or nonpublic personal information (NPI).

We recommend customers avoid entering borrower names, loan numbers, SSNs, or other NPI into workflow fields, and to use internal reference IDs or synthetic identifiers instead. We're happy to advise on naming conventions during onboarding.

Infrastructure

ThroughLine runs on Cloudflare's edge platform:

All traffic to ThroughLine is encrypted in transit (TLS). Data at rest in D1 and R2 is encrypted using Cloudflare's platform-level encryption.

Multi-tenancy and data isolation

Today, each customer runs on their own dedicated Worker and D1 database instance — there is no shared database or tenant-ID row-scoping mechanism, because there's no shared database to scope. Your data is physically separate from every other customer's, not just logically filtered.

As ThroughLine grows toward a shared, self-serve deployment model, this section will be rewritten to describe whatever tenant-isolation mechanism that architecture actually uses (e.g. per-tenant row scoping vs. per-tenant database) — we won't leave this describing the old model after the underlying architecture changes.

Access controls

Data retention

Incident response

If we discover a security incident affecting your data, our process is: contain it immediately (revoke access, rotate credentials, patch the vulnerability), assess what was actually affected, and notify affected customers without undue delay — no later than 72 hours after we confirm an incident involving customer data, by email to your account's Governance Contact.

We're a small team today (see Access controls above), so in practice this is a direct, founder-level response rather than a dedicated security operations process — but it's a real commitment we hold ourselves to, not a placeholder for one we'll write later.

What we don't have yet — and our roadmap

We believe in being upfront about this rather than implying otherwise:

Try before you trust

If you'd like to evaluate ThroughLine before entering any real organizational data, we encourage starting with synthetic or placeholder workflow data. This lets your team validate the product without any data-security conversation being a blocker up front.