Trust
AI governance
Last updated: September 29, 2026
Loomrail's agents act for people — they write, search, and work in connected apps. This page explains the controls around that: who stays in charge, which models run, what is recorded, and what happens when something goes wrong. See also Security.
People stay in charge
- Anything that reaches other people — emails, chat posts, calendar invitations, moving or cancelling meetings with guests — is shown in full first and happens only after the person says yes. The approval covers exactly what was shown and expires after 30 minutes.
- Changes in the person's own apps (a spreadsheet row, a task) happen only when they ask, and destructive ones check that the target hasn't changed since it was read.
- Per-person send limits cap how much an agent can send in a period.
- After an agent has read content from outside Loomrail, opening a website the person didn't name needs their yes — exact links from the agent's own web search are the exception, since they existed before the conversation and can't carry its data.
- Company admins decide which models, connected apps and data-masking rules apply to their members.
Models and transparency
- Each answer records which model produced it, visible in the reply's details.
- People choose a model or use Auto, which picks from an approved list; companies can restrict the list. Free or unnamed ("stealth") preview models are never offered, because their terms often let the provider keep what is sent.
- Models are from established providers (OpenAI, Anthropic, Google and others, listed on the Sub-processors page), used through business APIs that don't train on customer data. Loomrail doesn't train models on customer data.
- AI output can be wrong. The product says so, and people review what an agent produces before relying on it.
Data going to models
Only what a request needs is sent to a model. Secrets (API keys, passwords, tokens) are masked before any model sees them. Company admins can also mask emails, phone numbers, Aadhaar, PAN, card and bank details; masked values are restored only when an approved action needs them, such as the address an email goes to. Instructions found inside web pages, emails and files are treated as content, never as commands. Images from other websites in an answer load only when the person clicks, so an answer can't quietly send data to another site.
What is recorded
| Record | Who can see it | Kept |
|---|---|---|
| Chats, including each tool an agent ran | The person (and people they share a chat with) | Until deleted, or the company's retention period |
| Model and token usage per request | The person; Loomrail for billing | Until the account is closed |
| Company audit log (sign-ins, apps connected, messages sent, two-factor and policy changes, how many values were masked) | Company admins | 3 years |
| Loomrail staff actions on accounts | Loomrail admins | At least 1 year |
Incidents
AI or security incidents follow our written response plan: contain, assess, tell affected people and companies (companies within 48 hours), report to regulators as the law requires, then fix the cause. Report a problem to grievance@loomrail.com.