ClozeLoop Trust Center

Security

Last updated August 15, 2026

ClozeLoop maintains a written information security program covering the confidentiality, integrity, and availability of company and customer data. This page summarizes it. Customers and prospects can request the underlying policy documents, and a completed security questionnaire, by emailing info@clozeloop.com.

Program and ownership

The Chief Executive Officer owns the information security program. The program consists of written policies reviewed at least annually, documented operational controls, an annual risk assessment, annual security awareness training for all personnel, annual review of vendor and sub-processor security posture, and continuous monitoring through logging, alerting, and dependency scanning.

Encryption

Access control

Personnel

Background checks are conducted before access to customer confidential data is granted, where permitted by law. All personnel execute confidentiality and intellectual property agreements, acknowledge our policies on hire and at least annually, and complete security awareness training on hire and at least annually.

Secure development

Source code outside the application platform is maintained in private repositories with access limited to authorized personnel. Material changes to production code are reviewed before deployment. Automated static analysis, secret scanning, and dependency scanning run in continuous integration on every change. Secrets are held in encrypted platform secret stores and are never committed to source control or embedded in client-side code.

Vulnerability management

Vulnerabilities are triaged against documented remediation targets, measured from the date the vulnerability is confirmed.

SeverityRemediation target
Critical7 days
High30 days
Medium90 days
LowNormal development work

Where remediation cannot meet the target, a compensating control or accepted risk is documented in our risk register.

Security testing

ClozeLoop performs an application-level security review of its own implementation at least annually, covering data access controls and customer isolation, authentication and authorization, API and integration review, and dependency scanning. Findings and remediation actions are documented and retained.

Platform-level penetration testing is performed by our infrastructure providers under their own SOC 2 and equivalent attestation programs, and we retain those reports as part of our vendor records. We engage a qualified third party to perform penetration testing of our own application where required by a customer contract, by a regulatory obligation, or by a finding that warrants external testing.

ClozeLoop does not currently hold a SOC 2 or ISO 27001 attestation.

Logging and monitoring

Authentication events, administrative actions, deployments, and sub-processor API calls are logged. Logs are retained for a minimum of 30 days, and logs related to confirmed security incidents for at least three years. Logs related to a specific customer's account can be made available to that customer on written request, subject to the confidentiality of other customers' information.

Resilience

Customer data in production is backed up automatically by the hosting platform. Backups occur daily and are retained for 20 days in encrypted form. We validate the ability to restore from backup at least annually. Our targets are a recovery point objective of up to 24 hours and a recovery time objective of 48 hours from declaring a disaster, where the underlying hosting platform is available. These are targets, not contractual commitments, except where committed in writing in a customer contract.

Incident response

Any employee who suspects a security event must report it within four hours. We follow a documented process of preparation, identification, containment, eradication, recovery, and lessons learned, with a post-incident review within 30 days.

Where an incident is confirmed to be a breach affecting customer confidential information, we notify affected customers without undue delay and in any event within 72 hours of confirming the breach. Notification includes the nature of the incident, the categories of data affected, the steps we have taken, and any recommended customer actions.

Reporting a vulnerability

We welcome reports of suspected security vulnerabilities from customers and external researchers. Email info@clozeloop.com with enough detail to reproduce the issue. We will acknowledge a good-faith report, investigate, and communicate the outcome where appropriate. Please do not access, modify, or delete data belonging to others, degrade our services, or disclose the issue publicly before we have had a reasonable opportunity to address it.