Security

Security isn't a feature. It's the foundation.

Your meetings contain sensitive information. Loopion is designed to protect it — and to answer the questions your security team will actually ask.

🗑️

Zero-Day Audio Retention

Raw meeting audio is deleted the moment your summary and actions are delivered — not days later. If processing needs a retry, audio is held only until recovery completes (7-day absolute maximum). We never store recordings.

🎙️

No Biometric Voice Profiles

Loopion does not create or retain voiceprints or biometric voice profiles. Speakers are identified from meeting participant information, on-screen names, captions and timing — not stored biometrics.

🔐

Encrypted Everywhere

All customer data is encrypted in transit and at rest — transcripts, actions, calendar connections and account data alike. Credentials and tokens are stored encrypted.

🧱

Workspace Isolation

Every workspace is strictly isolated. Meetings, transcripts and actions are only ever visible inside the workspace they belong to — access from outside is impossible by design.

👥

Role-Based Access

Owners, managers and members each see exactly what their role allows. Meeting content is further restricted to the people who were actually in the meeting.

🧠

No AI Training On Your Data

Your meetings are never used to train shared AI models. Conversations are processed to produce your outputs — nothing more.

GDPR compliant

EU Data Residency

Customer data is hosted and processed within the European Union, supported by a documented list of subprocessors.

📡

Continuous Monitoring

Security events are monitored, logged and contained automatically, with full audit trails and documented incident-response procedures including 72-hour breach notification.

Data protection

Your data, protected at every level

Encryption

  • • Strong encryption for data at rest
  • • Encrypted connections for all data in transit
  • • Encrypted credential and token storage
  • • No plaintext secrets in logs or errors

Access Control

  • • Role-based access (owner, manager, member)
  • • Meeting content restricted to meeting participants
  • • Automatic session expiry and revalidation
  • • Protection against forged requests on every change

Infrastructure

  • • EU data residency for customer data
  • • Resilient, isolated cloud infrastructure
  • • Automated backups with point-in-time recovery
  • • Documented subprocessor list

Monitoring & Response

  • • Real-time security event logging
  • • Automated alerting on anomalies
  • • Full audit trail for sensitive operations
  • • Incident response with 72-hour breach notification
Compliance

Compliance & certifications

GDPR

Designed to support your GDPR obligations: EU data residency, export and deletion controls, and a DPA available to every customer.

UK DPA 2018

Registered with the UK Information Commissioner's Office (ICO) and operated in line with UK GDPR and the Data Protection Act 2018, with 72-hour ICO breach notification procedures.

SOC 2

Controls are designed around SOC 2 Type II principles — audit trails, access controls and monitoring. Formal certification is on our roadmap; we do not claim it today.

ISO 27001

Security management practices aligned with ISO 27001 principles. We do not currently hold the certification and don't claim otherwise.

Need to talk security?

Our team is ready to answer your security questions and provide documentation.