Security isn't a feature. It's the foundation.
Your meetings contain sensitive information. Loopion is designed to protect it — and to answer the questions your security team will actually ask.
Zero-Day Audio Retention
Raw meeting audio is deleted the moment your summary and actions are delivered — not days later. If processing needs a retry, audio is held only until recovery completes (7-day absolute maximum). We never store recordings.
No Biometric Voice Profiles
Loopion does not create or retain voiceprints or biometric voice profiles. Speakers are identified from meeting participant information, on-screen names, captions and timing — not stored biometrics.
Encrypted Everywhere
All customer data is encrypted in transit and at rest — transcripts, actions, calendar connections and account data alike. Credentials and tokens are stored encrypted.
Workspace Isolation
Every workspace is strictly isolated. Meetings, transcripts and actions are only ever visible inside the workspace they belong to — access from outside is impossible by design.
Role-Based Access
Owners, managers and members each see exactly what their role allows. Meeting content is further restricted to the people who were actually in the meeting.
No AI Training On Your Data
Your meetings are never used to train shared AI models. Conversations are processed to produce your outputs — nothing more.

EU Data Residency
Customer data is hosted and processed within the European Union, supported by a documented list of subprocessors.
Continuous Monitoring
Security events are monitored, logged and contained automatically, with full audit trails and documented incident-response procedures including 72-hour breach notification.
Your data, protected at every level
Encryption
- • Strong encryption for data at rest
- • Encrypted connections for all data in transit
- • Encrypted credential and token storage
- • No plaintext secrets in logs or errors
Access Control
- • Role-based access (owner, manager, member)
- • Meeting content restricted to meeting participants
- • Automatic session expiry and revalidation
- • Protection against forged requests on every change
Infrastructure
- • EU data residency for customer data
- • Resilient, isolated cloud infrastructure
- • Automated backups with point-in-time recovery
- • Documented subprocessor list
Monitoring & Response
- • Real-time security event logging
- • Automated alerting on anomalies
- • Full audit trail for sensitive operations
- • Incident response with 72-hour breach notification
Compliance & certifications
GDPR
Designed to support your GDPR obligations: EU data residency, export and deletion controls, and a DPA available to every customer.
UK DPA 2018
Registered with the UK Information Commissioner's Office (ICO) and operated in line with UK GDPR and the Data Protection Act 2018, with 72-hour ICO breach notification procedures.
SOC 2
Controls are designed around SOC 2 Type II principles — audit trails, access controls and monitoring. Formal certification is on our roadmap; we do not claim it today.
ISO 27001
Security management practices aligned with ISO 27001 principles. We do not currently hold the certification and don't claim otherwise.
Need to talk security?
Our team is ready to answer your security questions and provide documentation.