Audit started September 2026
In progressExpected in 8 to 12 weeks. Type II follows.
Trust & Security
You're trusting us with your strategy, your customers' words and your numbers. This page lists the controls we actually run, who else touches your data, and the gaps we're still closing, each with a date.
Last updated 25 September 2026 · next review when SOC 2 Type I completes
Expected in 8 to 12 weeks. Type II follows.
Running alongside SOC 2. We will publish the target date when it is confirmed.
Part of the audit work.
Railway holds SOC 2 Type II. Shorter Loop is not currently SOC 2 certified.
Data Residency
Customer application data is stored in the EU on every plan. AI processing is disclosed separately below.
Your data is stored in Railway's Frankfurt region. EU data residency is included in the base price.
Railway runs the servers, databases and storage volumes. Their SOC 2 Type II report covers the infrastructure layer. It doesn't cover our application, which is why we're getting our own.
If you need your own isolated infrastructure or a different region, it's available as an add-on because it costs us to run.
Access
On our side, one person. On yours, whoever you decide.
Production access is currently restricted to our CTO. Other team members use non-production environments and support tooling that does not require production-data access.
No change reaches our QA or production branches without an approved review.
Products are access boundaries. People see the products they've been given access to.
Data Protection
The controls we run today.
Traffic to Shorter Loop uses TLS. Stored data is encrypted at rest.
Every database and storage volume is backed up every 24 hours.
We run automated vulnerability scans against the application ourselves. A third-party test is scheduled as part of the audit.
GitHub code scanning and secret protection run on our repositories, so known vulnerable patterns and leaked credentials are caught before release.
AI data implications
What Sage sends, where it goes, and what it can reach.
Not ours, and not our AI provider's.
When Sage reads a document or answers a question, the relevant text is sent to the model provider for processing. Every call goes through one gateway we run, so we know exactly which services make calls and what they send
When you connect a tool over MCP, you choose which of its functions Sage may call. Until you choose, the connection sits unused. Sage reads through these connections and never writes to your tools.
Tokens for our MCP server are write-only by default. Read access is granted per token. No token can read your evidence or Sage's reasoning, and agents can't change anything a person created.
The full list. It's short on purpose.
| Entity | What they do for us | What they see | Location |
|---|---|---|---|
| Railway Inc. | Hosting, databases, storage | All customer data, encrypted | Frankfurt, DE |
| Anthropic | Runs the language models Sage uses | Text Sage sends for processing | US |
| OpenAI | Runs the language models Sage uses | Text Sage sends for processing | US |
| ZeptoMail (Zoho) | Sends notification and account email | Recipient address and message content | India |
| Google Workspace | Our own company email | Only what you email us | US |
Take it out or have it deleted whenever you want.
Everything you put in, and everything Shorter Loop produced from it, can be exported whenever you want.
Ask and we delete your data, including backups once they expire.
We sign a DPA with any customer who asks, countersigned by our founder. We also answer reasonable procurement security questionnaires.
So you don't have to find out in a procurement call.
Both audits are under way. Until they finish, we can walk you through the controls on this page and answer a security questionnaire.
Today we test ourselves. The external gray-box test is scheduled as part of the audit.
We don't pay bounties. We do read every report sent to the address below and credit you if you'd like.
We do not currently operate a 24/7 staffed security operations function.
One place to request policies, audit reports and the pen-test summary.
Or ask anything this page doesn't answer.
security@shorterloop.com
We reply within two working days. Please give us a chance to fix it before you publish.