Trust center
How we handle your software, your data and your risk
The questions a careful buyer asks before signing, answered in one place. Where the answer is no, it says no.
Ask a security questionYour code. Your accounts. Your call.
Ownership, in your name from day one
The single biggest risk in hiring a software firm is what happens if you want to leave. Here is how that works with us.
The code is yours
It sits in your own repository and belongs to you under the agreement we sign. You do not buy it back at the end.
The accounts are yours
Hosting, domain, platform and third-party services are in your name, paid on your card. We are users on them, not owners.
The data is yours
Your records stay in your accounts. On request we export them in a normal format and confirm deletion of what we held.
You can leave
Notice is written into the run arrangement. You get the instructions and a handover walkthrough whether you leave for another firm or take it in-house.
How we work day to day
Practices, not promises. Ask us to show any of these on the call.
Access is limited and reviewed
People get access to what their job needs and lose it when the job changes. Access is reviewed as people join and leave a project.
Traffic is encrypted
This website and the software we build are served over encrypted connections, and secrets live in the platform's secret storage rather than in code.
Changes are reviewed
Work is checked by another person before it goes live, and every change is recorded, so an audit can see who changed what and when.
Faults have an agreed time
Response times are written into your run arrangement, and the monthly report says what happened and what we fixed.
AI stays inside limits
Where we put AI live, it has firm limits on what it may do, a record of every request and reply, a person in the loop for anything risky, and a switch that turns it off.
NDAs as standard
We sign your NDA before the detail of a project is discussed, and we expect to.
What we do not claim
Every security page should have this section. Ours is short and true.
We do not hold SOC 2, ISO 27001 or an equivalent certification today. If your procurement requires one, tell us on the first call so nobody wastes a month.
We are not a hosting company. Your software runs on providers such as Netlify, Shopify or a cloud you choose, under their security posture as well as our practices.
We do not promise a number we have not measured. The uptime we publish is for software we run, and we will show you the report behind it.
Found something?
If you believe you have found a security problem in this website or in software we run, tell us. A named person replies within one business day, and we will tell you what we did about it.
Report it by emailhi@infoloop.co
Please include
- What you found, in plain words
- The steps to reproduce it
- Where you saw it: the address or the screen
- How we can reach you for the answer
Have a security questionnaire?
Send it over. We answer it ourselves rather than passing it to a form, and we tell you plainly which rows we cannot tick.