Security and trust
Loomiq holds regulated firms' client, placement, claims and financial records. These are the controls that protect them.
Last updated 5 October 2026
Signing in
- Two-step verification with an authenticator app or a passkey, which a firm can require for its administrators or for everyone.
- Single sign-on with Microsoft Entra ID or Google Workspace, limited to the firm’s own domains and existing accounts.
- Sign-in lockout after repeated failures, rate limits on public endpoints, sessions that end after at most 12 hours, and sessions revoked everywhere on a password change.
Keeping each firm’s data separate
- Every firm is a separate tenant. Each request is scoped to the user’s firm and, for roles that work their own book, to the records they work on.
- An automated isolation test suite checks, on every change, that one firm cannot read or change another firm’s records.
- Platform administrators manage the platform, not your data: they can see a firm’s records only under time-limited support access that the firm grants, can revoke, and that is audited.
Audit trail
Every change to data is written to an append-only audit trail with who made it, when and the values before and after. The trail is hash chained per firm, so any alteration is evident.
Application security
- TLS for every connection, with HTTP Strict Transport Security.
- A content security policy, cross-site request checks and security headers on every response.
- Outbound calls go through a guard that only allows public, encrypted addresses.
- Every API route declares its authentication, roles, scope, input validation and audit, and is denied by default if it does not.
Data protection and residency
- Each firm and legal entity has a home data region. Today, data is hosted in the UK and EU region, on Railway in Amsterdam, with nightly backups in the same region.
- A record of processing and a sub-processor register are available to each firm’s compliance team.
- Retention rules anonymise regulated records at the end of their retention period, after approval by two people.
AI governance
- All AI goes through one router: providers, models, budgets and kill switches are set by administrators, and every configuration change is versioned and audited.
- Client documents go only to providers approved for confidential data, and providers outside the data’s region are skipped.
- AI requests are logged without their prompt or response content.
- Nothing the AI proposes is written until a person approves it.
Sub-processors
- Railway: application, database and document storage hosting (EU West, Amsterdam).
- Resend: email delivery (United States, under the EU Standard Contractual Clauses and the UK Addendum).
- AI providers chosen by the firm’s administrators (Anthropic by default), listed in the firm’s sub-processor register.
Reporting a vulnerability
If you think you have found a security issue in Loomiq, please tell us at help@loomiq.io. Give us a reasonable time to fix it before telling anyone else, and do not access or change data that is not yours. We will acknowledge your report and keep you informed.