Skip to main content

Security and trust

Loomiq holds regulated firms' client, placement, claims and financial records. These are the controls that protect them.

Last updated 5 October 2026

Signing in

  • Two-step verification with an authenticator app or a passkey, which a firm can require for its administrators or for everyone.
  • Single sign-on with Microsoft Entra ID or Google Workspace, limited to the firm’s own domains and existing accounts.
  • Sign-in lockout after repeated failures, rate limits on public endpoints, sessions that end after at most 12 hours, and sessions revoked everywhere on a password change.

Keeping each firm’s data separate

  • Every firm is a separate tenant. Each request is scoped to the user’s firm and, for roles that work their own book, to the records they work on.
  • An automated isolation test suite checks, on every change, that one firm cannot read or change another firm’s records.
  • Platform administrators manage the platform, not your data: they can see a firm’s records only under time-limited support access that the firm grants, can revoke, and that is audited.

Audit trail

Every change to data is written to an append-only audit trail with who made it, when and the values before and after. The trail is hash chained per firm, so any alteration is evident.

Application security

  • TLS for every connection, with HTTP Strict Transport Security.
  • A content security policy, cross-site request checks and security headers on every response.
  • Outbound calls go through a guard that only allows public, encrypted addresses.
  • Every API route declares its authentication, roles, scope, input validation and audit, and is denied by default if it does not.

Data protection and residency

  • Each firm and legal entity has a home data region. Today, data is hosted in the UK and EU region, on Railway in Amsterdam, with nightly backups in the same region.
  • A record of processing and a sub-processor register are available to each firm’s compliance team.
  • Retention rules anonymise regulated records at the end of their retention period, after approval by two people.

AI governance

  • All AI goes through one router: providers, models, budgets and kill switches are set by administrators, and every configuration change is versioned and audited.
  • Client documents go only to providers approved for confidential data, and providers outside the data’s region are skipped.
  • AI requests are logged without their prompt or response content.
  • Nothing the AI proposes is written until a person approves it.

Sub-processors

  • Railway: application, database and document storage hosting (EU West, Amsterdam).
  • Resend: email delivery (United States, under the EU Standard Contractual Clauses and the UK Addendum).
  • AI providers chosen by the firm’s administrators (Anthropic by default), listed in the firm’s sub-processor register.

Reporting a vulnerability

If you think you have found a security issue in Loomiq, please tell us at help@loomiq.io. Give us a reasonable time to fix it before telling anyone else, and do not access or change data that is not yours. We will acknowledge your report and keep you informed.

Security and trust | Loomiq