Legal
Security
How we keep your workflows and data safe.
Last updated: July 2026
Our approach to security
Security is foundational to how we build Loopyback. Because our Service captures screenshots of real workflows, we design every layer — from the browser extension to our backend infrastructure — with the assumption that the data we handle is sensitive. We follow the principle of least privilege, defense in depth, and secure-by-default configuration across our systems.
Encryption (in transit & at rest)
All data transmitted between your browser and our servers is encrypted in transit using TLS 1.2 or higher. Data at rest, including your captured screenshots and guides, is encrypted using AES-256. Encryption keys are managed through a dedicated key management service with strict access controls and regular rotation.
Automatic PII redaction
Loopyback automatically scans captured screenshots for common categories of personally identifiable information — such as email addresses, phone numbers, payment card numbers, and access tokens — and blurs them before content is stored. This reduces the risk of sensitive data being inadvertently captured or shared.
Automatic redaction is a safeguard rather than a guarantee, so we recommend reviewing each guide before sharing it. You can manually redact additional regions at any time.
Access controls & SSO
Access to your data is governed by role-based permissions within your workspace, so only authorized team members can view or edit guides. For organizations, we support single sign-on (SSO) via SAML and OIDC, along with SCIM provisioning to automate user onboarding and offboarding.
Internally, employee access to production systems is restricted, logged, and requires multi-factor authentication. Access is granted on a need-to-know basis and reviewed regularly.
Infrastructure & hosting
Loopyback runs on leading cloud infrastructure providers that maintain industry-recognized certifications for physical and environmental security. Our environments are isolated by network segmentation, protected by firewalls, and continuously monitored. We maintain automated backups and a tested disaster recovery plan to preserve availability and data integrity.
Compliance (SOC 2 in progress)
We are actively pursuing SOC 2 Type II certification and have implemented the corresponding controls across our organization. We align our practices with recognized frameworks and support GDPR and CCPA compliance for our customers. If your organization requires a security review or documentation, our team is happy to help.
Responsible disclosure
We welcome reports from security researchers who help us keep Loopyback safe. If you believe you have found a vulnerability, please report it to us privately and give us a reasonable opportunity to investigate and remediate before any public disclosure. We commit to acknowledging reports promptly and will not pursue legal action against researchers acting in good faith.
Contact the security team
To report a vulnerability or ask a security question, contact our security team at security@loopyback.com. We respond to all reports as quickly as possible.