Security & Compliance

An RIA's compliance team asks harder questions than a demo audience does. Here is what's actually true about how Thesis is built.

Each firm's data is isolated at the database level

Thesis is multi-tenant software: every firm on the platform shares the same application, but not the same data. Every query is scoped to your firm both in the application code and independently at the database layer, so one firm's reports, portfolios, and onboarding records are structurally unreachable from another firm's account — not just hidden by the interface.

An audit trail that can't be quietly edited

Every report generated, every onboarding decision, and every data source touched is logged to a record that the database itself refuses to let anyone modify or delete after the fact — not a setting an admin can turn off, an enforced property of the storage layer. "The AI said so" is never going to be an acceptable answer to a regulator; this is what a real answer is built on.

Role-based access, not one shared login

Every user in your firm's account has a role — Owner, Admin, Advisor, Analyst, or Viewer — and what they can see and do is scoped to that role, not to whoever happens to be logged in. Report generation, portfolio analysis, onboarding review, and account administration are gated independently.

What Thesis is, and isn't

Thesis is a software platform, not a Registered Investment Advisor, broker-dealer, or fiduciary. Reports and analysis are generated for informational and professional research purposes — not a recommendation or solicitation to buy, sell, or hold any security. Your firm remains responsible for how its output is used with clients.

Have a specific vendor-review or due-diligence question?

Contact us