
International standard for information security management. Thryve's infrastructure, processes, and data handling are independently audited against the highest security requirements.
Quality management certification ensuring consistent, reliable service delivery — the only wearables API to hold both ISO certifications.
Full compliance with US healthcare data protection law. BAA agreements included on all plans — no enterprise upgrade required.
Built for European data protection law from the ground up. Data Processing Agreements included as standard, with full data residency controls.
Third-party security audits conducted annually to identify and close vulnerabilities — a requirement of ISO 27001 and HIPAA security standards.
Raw health data is tokenized at ingestion, meeting GDPR data minimization principles and HIPAA Safe Harbor requirements.
Business Associate Agreements and Data Processing Agreements are standard on every plan — documents your legal team will ask for, already taken care of.