Skip to content

Legal

Security overview

Last updated June 1, 2026

A summary of the controls behind the product. If you need our full security questionnaire, architecture diagram or penetration test summary for a vendor review, email security@looph.io and we will send them.

Infrastructure and isolation

The service runs on managed cloud infrastructure in hardened, private networks. Every query is scoped to a workspace at the data layer, so tenant isolation does not depend on application code getting a filter right.

Encryption

TLS 1.2 or above for all traffic, HSTS on every public domain, and AES-256 at rest for databases, object storage and backups. Secrets are held in a managed vault and rotated on a schedule.

Access control

SSO and SAML for workspace members, granular roles inside the product, mandatory MFA for our staff, least-privilege production access and full audit logging of administrative actions.

Resilience

Point-in-time recovery with a 24-hour objective, daily encrypted backups, restore drills each quarter and a documented incident response runbook with named on-call ownership.

Application security

Peer review on every change, automated dependency scanning, static analysis in CI, rate limiting and bot protection on public endpoints, and annual third-party penetration testing.

Responsible disclosure

Report a vulnerability to security@looph.io. We acknowledge within one business day, will not pursue legal action for good-faith research that respects customer data, and credit reporters who want it.