Trust Center

Last updated: September 20, 2026

1. What We Do Not Have

Most trust pages open with certifications. Ours opens with their absence, because you are going to ask and the answer should not be buried.

  • No SOC 2 report. We have not completed a SOC 2 Type I or Type II audit.
  • No ISO 27001 certification. We are not certified.
  • No third-party penetration test. We have not commissioned one.
  • No PCI DSS or HIPAA attestation. We do not store card numbers; payments run through a merchant of record. We are not set up for protected health information.
  • One hosting region. There is no regional choice today. See below for where your data actually sits.

If any of these is a requirement for your company, we would rather you know now than three months into a rollout. Tell us which one and we will tell you honestly whether it is on the roadmap.

2. Where Your Data Lives

  • Application, database and files. Servers operated by Hostinger International Ltd. in Kuala Lumpur, Malaysia. That is one region, and it is the only one.
  • Network edge. Cloudflare handles DNS, delivery and network protection, and processes connection data such as IP addresses across its global network.
  • Some processors are elsewhere. Sign-in, email delivery, payments and the AI models run in the United States. Each one, what it receives and where it is, is listed on the Subprocessors page.

If your company is required to keep operational data inside a specific jurisdiction, this is the constraint to weigh before anything else on this page.

3. How Tenants Are Kept Apart

This is the part we would want to inspect if we were buying, so it is stated concretely rather than as a promise.

  • The database enforces it, not the application. Every request runs as a restricted PostgreSQL role, and row-level security decides which company's rows that role can see. Application code cannot widen it.
  • It is tested, and the test can fail. A workspace-scoped table with row-level security disabled fails the build. We hold ourselves to the rule mechanically rather than by review.
  • Permissions reach fields and records. Administrators decide what each role sees and does, and the same rules bind people and AI agents.
  • Separation of duties. On Business, whoever creates a change cannot also approve it.
  • An audit trail. Changes record what changed, when, and who or which agent made it.

4. AI, Specifically

An AI agent in Loopency is an actor inside the same model as a person, not an interface over it. It passes the same permission checks, the same approval rules and the same audit trail.

  • An agent cannot see a record a person in that role could not see. Reading is authorized the same way writing is.
  • Personal identifiers are masked before anything is sent to a model.
  • Your data is not used to train anyone's model.
  • Monitoring traces carry no prompt, reply, tool argument or tool result.

The full policy is at AI Usage Policy.

5. Reporting a Vulnerability

Email [email protected] with "Security" in the subject, the steps to reproduce and the impact. If you act in good faith we will not pursue legal action, we will respond, and we will tell you when it is fixed. We do not run a paid bug bounty.

The full terms, including what we ask you not to do, are in Security.

6. Documents

Trust Center - Loopency