Trust center

How Loops protects the calls you send us

Loops reads your agents' calls to grade them. Here is exactly what it can touch, where the data lives and what we sign before any access.

The security packet holds our SOC 2 Type II report and bridge letter, the subprocessor list and our policies. It's shared under NDA. Choose "Security packet" on the form and we'll reply within one business day.

Compliance

SOC 2

Type II The report and a bridge letter are available under NDA with the security packet.

HIPAA

We sign a BAA before we receive any access to a healthcare customer's calls.

GLBA

For lenders and servicers, our DPA covers consumer financial information and supports your Safeguards Rule oversight of service providers.

Agreements first

An NDA and DPA are signed before any key changes hands. We complete your security questionnaire on request.

Your regulations

Loops checks calls against FDCPA, Reg F, TCPA and HIPAA rules you approve. It supports your program; it doesn't replace your counsel.

Access to your platform

  • Reads calls, nothing else. Where a key can be limited to reading, as on ElevenLabs, we ask for that. Where it can't, as on Retell, Vapi and Bland, we use a dedicated key only to read calls and log every request. Or send finished calls by webhook and give us no key at all.
  • Never writes to your agent. Loops never calls anything that changes a prompt, flow, setting or phone number, and the request log shows it. Suggested fixes arrive as drafts your team reviews.
  • Test calls are opt-in. Pre-release runs dial a test agent you name, using a separate key, and your platform bills those minutes as usual.
  • Revoke any time. Revoke the key and Loops stops at once.

Your data

  • US only. Call data is stored and processed in the United States.
  • Encrypted with TLS 1.2 or higher in transit and AES-256 at rest.
  • No training. Nothing you send trains any model, ours or a provider's.
  • Retention you set, and deletion on request. If you don't continue after the free audit, we delete your calls, transcripts and recordings within 30 days and confirm it in writing. You keep your report either way.
  • Named access. Only named staff can open a call, only to answer a question you raised, and every view and export is logged.
  • Subprocessors. The full list comes with the security packet.

If something goes wrong

If a security incident affects your data, we tell your named security contact within 72 hours of discovering it, with what was affected and what we did about it. Your DPA, and your BAA for healthcare, hold us to this.

This website

  • No cookies, no analytics and no third-party scripts or fonts. See the cookie policy.
  • HTTPS everywhere, with a content security policy, HSTS and frame, referrer and content-type protections.
  • Policies: privacy, cookies, terms.

Report a security issue

If you believe you've found a vulnerability, tell us through the form (choose "Security packet" and add a note) and we'll reply within one business day with a secure way to send the details. Please give us reasonable time to fix it before sharing it publicly, and don't access data that isn't yours. We won't take legal action against good-faith research that follows this policy. Our security.txt points here.