Trust & Security

What we protect, how we protect it, and what we haven't done yet.

You're trusting us with your strategy, your customers' words and your numbers. This page lists the controls we actually run, who else touches your data, and the gaps we're still closing, each with a date.


Last updated 25 September 2026 · next review when SOC 2 Type I completes


SOC 2 Type I

Audit started September 2026

In progress

Expected in 8 to 12 weeks. Type II follows.

ISO 27001

Running alongside SOC 2

In progress

Running alongside SOC 2. We will publish the target date when it is confirmed.

Penetration test

Third-party, gray-box

Scheduled

Part of the audit work.

Hosting

Railway, Frankfurt

In place

Railway holds SOC 2 Type II. Shorter Loop is not currently SOC 2 certified.

Data Residency

Where your data lives

Customer application data is stored in the EU on every plan. AI processing is disclosed separately below.

Frankfurt, Germany

Every plan

Your data is stored in Railway's Frankfurt region. EU data residency is included in the base price.

Railway Inc. infrastructure

SOC 2 Type II

Railway runs the servers, databases and storage volumes. Their SOC 2 Type II report covers the infrastructure layer. It doesn't cover our application, which is why we're getting our own.

Isolated region

Enterprise add-on

If you need your own isolated infrastructure or a different region, it's available as an add-on because it costs us to run.

Access

Who can see it

On our side, one person. On yours, whoever you decide.

One person has production access

In place

Production access is currently restricted to our CTO. Other team members use non-production environments and support tooling that does not require production-data access.

Every code change is reviewed

In place

No change reaches our QA or production branches without an approved review.

Roles inside Shorter Loop

Every plan

Products are access boundaries. People see the products they've been given access to.

Data Protection

How it's protected

The controls we run today.

Encryption in transit and at rest

In place

Traffic to Shorter Loop uses TLS. Stored data is encrypted at rest.

Daily backups

In place

Every database and storage volume is backed up every 24 hours.

Vulnerability scanning

In place

We run automated vulnerability scans against the application ourselves. A third-party test is scheduled as part of the audit.

Code and secret scanning

In place

GitHub code scanning and secret protection run on our repositories, so known vulnerable patterns and leaked credentials are caught before release.

AI data implications

AI and your data

What Sage sends, where it goes, and what it can reach.

Your data isn't used to train models

Policy

Not ours, and not our AI provider's.

Your data does reach an AI provider

Disclosed

When Sage reads a document or answers a question, the relevant text is sent to the model provider for processing. Every call goes through one gateway we run, so we know exactly which services make calls and what they send

Sage only reads what you allow

In place

When you connect a tool over MCP, you choose which of its functions Sage may call. Until you choose, the connection sits unused. Sage reads through these connections and never writes to your tools.

Agents write, and see little

In place

Tokens for our MCP server are write-only by default. Read access is granted per token. No token can read your evidence or Sage's reasoning, and agents can't change anything a person created.

Who else touches your data

The full list. It's short on purpose.

EntityWhat they do for usWhat they seeLocation
Railway Inc.Hosting, databases, storageAll customer data, encryptedFrankfurt, DE
AnthropicRuns the language models Sage usesText Sage sends for processingUS
OpenAIRuns the language models Sage usesText Sage sends for processingUS
ZeptoMail (Zoho) Sends notification and account emailRecipient address and message contentIndia
Google WorkspaceOur own company emailOnly what you email usUS

Your data stays yours

Take it out or have it deleted whenever you want.

Export any time

Every plan

Everything you put in, and everything Shorter Loop produced from it, can be exported whenever you want.

Deletion on request

Every plan

Ask and we delete your data, including backups once they expire.

Data processing agreement

Available

We sign a DPA with any customer who asks, countersigned by our founder. We also answer reasonable procurement security questionnaires.

What we don't have yet

So you don't have to find out in a procurement call.

Expected Q4 2026

A SOC 2 or ISO 27001 report you can read

Both audits are under way. Until they finish, we can walk you through the controls on this page and answer a security questionnaire.

With the audit

A third-party penetration test

Today we test ourselves. The external gray-box test is scheduled as part of the audit.

Not planned yet

A bug bounty program

We don't pay bounties. We do read every report sent to the address below and credit you if you'd like.

Not planned yet

24/7 security operations

We do not currently operate a 24/7 staffed security operations function.

Planned

A trust center

One place to request policies, audit reports and the pen-test summary.

Report a vulnerability

Or ask anything this page doesn't answer.

security@shorterloop.com

  • What you found and where
  • Steps to reproduce it
  • What an attacker could do with it

We reply within two working days. Please give us a chance to fix it before you publish.