Compliance
Assistant operations need clear boundaries and reviewable signals.
This page summarizes Thalovant's compliance posture for private hubs, public hub publishing, BYOS, accounts, access control, telemetry, incidents, provider review, and Quebec/Canada operating expectations.
Product Boundaries
Thalovant separates public hub discovery from private workspace operation. Users can keep hubs private, expose public hubs to the world, and bring their own skills while retaining responsibility for the content, sources, and services they publish or connect.
OpenVoiceOS skills, community skills, and BYOS skills remain the responsibility of the publisher, operator, or user who installs, connects, or exposes them unless Thalovant expressly identifies a skill as Thalovant-managed.
Quebec And Canada Privacy Governance
Thalovant's privacy governance is organized around a privacy officer contact, privacy-by-design review for new data flows, consent records for optional analytics, confidentiality incident records, provider review, and cross-border transfer assessments where required by Quebec privacy law.
Product design minimizes unnecessary personal information, keeps public/private visibility explicit, and makes access, telemetry, billing posture, and workspace ownership understandable to account operators.
Security, Access Controls, And Operations
The product is designed around tenant ownership, scoped access, hub and client specifications, role posture, ACL policy, protected authentication flows, and auditable workspace actions.
Thalovant surfaces telemetry, watcher events, status history, billing posture, GitOps context, runtime health, and connection state so assistant infrastructure can be reviewed instead of treated as a black box.
Incidents, Commercial Messages, And Providers
If Thalovant identifies a confidentiality, security, availability, or abuse incident, Thalovant should investigate, contain, preserve relevant records, communicate operational status, and notify affected users or regulators where legally required.
Commercial electronic messages should be sent only with consent or another lawful basis, identify the sender, include required contact details, and provide an unsubscribe mechanism where anti-spam rules apply.
Service providers should be limited to the access needed for hosting, payments, analytics when consented, authentication, support, monitoring, security, and infrastructure operations.
Compliance Claims And Enterprise Review
This page does not claim SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or other formal certification unless Thalovant separately publishes that certification. Enterprise deployments may require security questionnaires, procurement review, data processing terms, deployment architecture review, SSO, SLA commitments, or additional controls.
Security questions can be sent to security@thalovant.com. Privacy questions can be sent to privacy@thalovant.com.