Trust

Security

Last updated: September 29, 2026

Back

How Loomrail protects the data you and your company put in it. For what we collect and your rights, see the Privacy Policy; for company terms, the DPA; for who processes data, the Sub-processors list; for how the AI is governed, the AI governance page.

Hosting and data location

Loomrail runs on Google Cloud (Singapore) with its database on Neon (Singapore). The web app is served by Vercel. Application logs are kept for 365 days in Google Cloud's Mumbai region, India.

Encryption

  • All traffic uses HTTPS (TLS), with HSTS on the web app and API.
  • Databases, files and backups are encrypted at rest by our hosting providers.
  • Tokens for apps you connect (Google, Microsoft, Slack…) are additionally encrypted by Loomrail with AES-256-GCM, using a key held in Google Secret Manager.
  • Passwords are stored only as salted bcrypt hashes.
  • Files are never public: they're served through signed links that stop working after 12 hours.

Access control

  • Everything requires sign-in; you can sign out of every device from Settings → Security, and changing a password, email or role signs the account out everywhere.
  • Two-factor sign-in with an authenticator app (with one-time backup codes) is available to everyone, required for Loomrail admins, and can be required by a company for its members. Wrong codes are rate-limited and a code can't be reused.
  • Companies can require sign-in through Google Workspace, Microsoft Entra or any SAML identity provider (Okta, OneLogin, Ping and others) for their email domain, and manage members and admin roles. SAML responses must be signed by the company's own identity provider and can be used only once.
  • Companies can connect their directory with SCIM so people are added, updated and turned off automatically — someone who leaves loses access straight away.
  • Setup guides for admins: single sign-on and automatic provisioning (SCIM).
  • Loomrail staff work under least-privilege roles, and every staff action on an account is written to an audit log.
  • Company admins get their own audit log of member activity (sign-ins, connected apps, messages sent by agents, policy changes) — activity only; admins can't read members' chats.

AI safeguards

  • An agent never sends an email, posts, or sends invitations without showing you exactly what it will send and getting your yes; there are per-person send limits.
  • Instructions hidden inside web pages, emails or files are treated as data, not commands.
  • After an agent has read outside content, it asks before opening a website you didn't name, so injected instructions can't carry your data out in a link. Images from other websites in a reply load only when you click them.
  • Secrets such as API keys and passwords are masked before text reaches an AI model; companies can also mask contact, ID and financial details.
  • AI models are used through business APIs that do not train on your data, and Loomrail doesn't train models on it either. Free or unnamed preview models are not offered. Companies can limit which models their members use.

Your data, your control

Export your data or close your account any time; closing an account deletes its data and files. Companies set how long chats are kept, and can export or delete their members' data.

Incidents

We keep a written breach-response plan. If a breach affects your data we tell you — and for companies, within 48 hours — and we report to the Data Protection Board of India and CERT-In as the law requires.

Compliance status

Status
India DPDP Act 2023Consent, rights, Grievance Officer, breach plan and retention in place
EU / UK GDPRDPA with Standard Contractual Clauses for company customers
Independent penetration testPlanned
SOC 2 Type IPlanned

Report a security issue

Found a vulnerability or have a security question? Email grievance@loomrail.com with the subject "Security". Please give us a chance to fix an issue before sharing it publicly.