ThunderPhone is GDPR, HIPAA, and UK GDPR compliant. We document our controls, monitor them continuously, and enforce security policies across the platform.
How ThunderPhone meets requirements for personal data, privacy, and protected health information.
Sets requirements for handling and protecting personal data belonging to people in the European Union.
Sets U.S. safeguards for protected health information handled for healthcare customers and their patients.
Sets requirements for handling and protecting personal data belonging to people in the United Kingdom.
107 documented controls cover product, data, network, app, endpoint, and corporate security. Each is monitored continuously.
40 policies and supporting documents are available on request. We review each request before sharing them.
These vendors help us operate ThunderPhone. Each is covered by a data processing agreement.
19 more subprocessors. See the full list in the DPA.