Security

Security at thirds.ai

How thirds.ai isolates renders, protects data, limits storage, makes backups, uses service providers, and handles security reports.

Last updated 17 September 2026

We build thirds.ai to handle untrusted HTML, images, templates, and data. This page explains the controls that protect customer work and the service. It does not claim a security certificate.

Render isolation

Rendering runs outside the website and API services. Each render gets a fresh browser context in a pinned Chromium worker. The worker runs as an unprivileged user with a read-only system, a browser sandbox, and a restricted system-call profile. It has hard limits for time, memory, CPU, processes, pages, assets, and output size.

Render workers cannot make a direct public network request. Remote HTTP and HTTPS assets go through a controlled gateway. The gateway blocks private, loopback, link-local, metadata, reserved, and malformed destinations. It checks DNS answers and every redirect again. It never sends customer cookies, authorization headers, or service secrets to an asset host.

Data access and file checks

Customer files use random names that do not contain account details or original file names. Product file folders allow access only to the service user. A file read checks that the file is regular, inside its size limit, and matches the SHA-256 value in its database record.

Signed download links last 15 minutes. Finished files use private, no-store responses and do not appear in the sitemap, feeds, or public search pages.

Retention and deletion

  • We delete render input when the render ends.
  • We keep a finished PDF or static image for 30 days. You can delete it sooner.
  • We keep an anonymous playground output for one hour.
  • We keep your template chat inputs and accepted drafts until you delete the chat or close your account. Hidden AI attempts and temporary brand copies are removed after the message ends.
  • Account closure revokes access, cancels live work, and removes customer files and account access data through a repeat-safe cleanup process.

We keep limited financial, legal, and security records after account closure when we must meet those duties. These records do not keep customer document content.

Encryption in transit

Public website and API traffic uses HTTPS and TLS. Our public edge adds HTTP Strict Transport Security. Connections to the AI and analytics providers use fixed HTTPS destinations.

Backups and recovery

Each environment has a separate Cloudflare R2 backup bucket and access key. Backups include the database, finished account outputs, saved template versions, and accepted brand assets. Render input, AI chat content, anonymous playground output, hidden AI previews, and download signing keys are not backed up.

Database logs move to backup storage after each log segment completes. Account outputs, templates, and brand assets are copied every 15 minutes. We keep the newest seven database base backups and the logs they need. A restore check matches database records to the exact file size and SHA-256 value before the service can use restored templates or brand assets.

Service providers

We use a small set of service providers to run the service:

  • Hetzner Online GmbH hosts the live application, database, and file storage in Finland.
  • Cloudflare provides bot checks and R2 backup storage.
  • Resend sends sign-in and account email.
  • GitHub and Google confirm your identity when you choose their sign-in option.
  • OpenRouter and an eligible model host process the content you send to the template builder. That provider may use this content to improve its models.
  • PostHog Cloud in the EU stores the limited product analytics listed in our Privacy policy.
  • Stripe runs checkout and payment processing.

The Data processing agreement gives more detail about processing and these providers.

Billing and abuse controls

The API owns render admission, retry safety, and billing. A successful and fully checked file can spend a render credit. A failed internal render does not spend a credit. Separate limits stop repeated failed work from using the service without limit.

Report a security problem

Email support@thirds.ai with the subject “Security report.” Include the affected page or request ID, the impact, and clear steps to repeat the problem. Do not send API keys, passwords, private documents, or live exploit data in email.

We review each report and tell you when we need more information. The service status page shows current service impact and past incidents.

Ready to make the next file?

Start from a gallery template, change the words to yours, and download the finished file.