Skip to content
Unify Loop
Trust

Security, stated plainly — including what we haven’t done yet.

Unify Loop holds your customer relationships, your conversations, and your revenue data. This page describes how that is protected, and is explicit about the certifications we do not yet hold.

Tenant isolation enforced in the query engine

Every read and write is scoped to a workspace by the same engine that compiles your filters. Isolation is not a WHERE clause each feature remembers to add — it is applied where queries are built, so a feature cannot forget it. Row- and field-level permissions are applied in the same place, which is why they hold identically in the UI, the API, imports, workflows, and AI.

Encryption and access control

Data is encrypted in transit with TLS and at rest at the storage layer. Access to production is restricted, individually attributed, and logged. Sessions use short-lived access tokens with rotating refresh tokens, so a stolen token has a narrow window rather than an open one.

AI that cannot exceed the user

The AI reads and writes through the same object and query layer as every screen, so it inherits tenant scoping and role permissions rather than re-implementing them. There is no separate index with looser scoping — which is the usual reason bolted-on CRM AI leaks across tenants.

Operational practice

What we actually do.

Concrete practices rather than adjectives — each of these is something you could ask us to demonstrate.

  • Least-privilege access to production, individually attributed and logged
  • Automated encrypted backups with tested restores
  • Dependency and container scanning in CI, with builds blocked on known critical vulnerabilities
  • Audit trail of record changes, including anything AI wrote, with the actor recorded
  • Every AI message labelled as AI on the timeline
  • Consent, opt-out, and quiet hours enforced at the send layer rather than per feature
  • Secrets held in a managed store, never in source control
  • Separate sandbox workspaces on Scale so testing never touches live data
Being straight about it

What we are not claiming.

A security page that only lists strengths is not a security page. These are the honest gaps as of today.

  • No SOC 2 or ISO 27001 report yet. The controls exist; the third-party audit does not. We would rather lose a deal on that than win one on a badge we have not earned.
  • Data residency is Enterprise-only. It requires contractual commitments and infrastructure placement, so it is not a setting on a self-serve plan.
  • We use third-party model and messaging providers. AI inference and message delivery involve subprocessors. We can provide the current list on request, and none of them are permitted to train on your data.
  • No published uptime SLA outside Enterprise. We monitor and we care, but a contractual SLA is part of an Enterprise agreement rather than a self-serve promise.
FAQ

Security, answered.

Do you use our data to train AI models?

No. Your workspace data is used to answer your prompts and produce your results, and nothing else. We do not train models on customer data, and we do not permit our model providers to train on data we send them.

Are you SOC 2 or ISO 27001 certified?

Not yet, and we will not claim otherwise. The controls described on this page are how the system is built; a formal audit is a separate exercise with a timeline we have not completed. If certification is a procurement requirement for you, contact us and we will tell you honestly where we are rather than what you want to hear.

Where is data hosted, and can we choose the region?

Production runs in a managed cloud environment with encrypted storage and automated backups. Region selection and data residency commitments are available on Enterprise, since they involve contractual terms rather than a toggle.

Can we restrict who sees particular fields?

Yes. Permissions apply at row and field level and are enforced by the query engine, so a restricted field is invisible through views, reports, exports, the API, and the AI alike — not just hidden in the UI.

What happens to our data if we cancel?

You export it in full — CSV from any view, or through the API. After cancellation, data is retained for a limited window so an accidental cancellation is recoverable, then deleted. We do not restrict export as a retention tactic.

How do we report a vulnerability?

Email security@unifyloop.com with enough detail to reproduce it. We will acknowledge receipt, keep you updated while we investigate, and credit you if you would like to be credited. We will not pursue action against good-faith research that avoids privacy violations, data destruction, and service disruption.

Security questions, questionnaires, or vulnerability reports: security@unifyloop.com. See also our privacy policy.

Have a security review to get through?

Send us the questionnaire. You will get direct answers, including where the answer is “not yet”.

Free trial · no card required · every price published