Security · Trust · Compliance
How we handle your data and your AI keys.
Specific commitments, named subprocessors, and an honest distinction between what we ship today, what we're building, and what we don't pursue. Built for teams that have to defend a tool choice through procurement and security review.
Last updated: 2026-05-22
Data
Per-workspace isolation, encryption at rest and in transit.
Infrastructure
Named hosting, database, and edge subprocessors.
Access
Roles, 2FA, SSO, and the full audit trail.
Compliance
GDPR today; SOC 2 and residency on the roadmap.
Policies
Bounded AI, vulnerability disclosure, incident response.
Status legend
Each commitment below carries one of three flags so you know exactly what is true today versus on the roadmap.
1. Data isolation
LiveCustomer Data is partitioned per Workspace at the database layer. Per-app evidence libraries are scoped per-Workspace; signals from one Operator’s app do not feed another Operator’s recommendations. There is no global learning model, and no cross-Operator embedding pool that would create signal leakage.
Workspace boundaries are enforced at every API endpoint and every algorithm-layer read path. Cross-Workspace reads are not possible without an explicit Teams parent-child relationship configured by ASOLOOP Operations.
2. Encryption
Live- In transit: TLS 1.2 minimum (TLS 1.3 preferred) for all traffic between client, marketing site, application, API, and subprocessors. HSTS enabled on all public domains.
- At rest: AES-256 encryption on the primary database, object storage, and backups. Encryption keys managed by the cloud-provider KMS with workspace-scoped envelope encryption for sensitive fields (BYOK API keys, MMP credentials).
- Key rotation: Provider-managed master keys rotate per provider policy; workspace data-encryption keys rotate on credential rotation events.
3. Connect Your AI Model (BYOK key handling)
LiveGenerative surfaces in ASOLOOP (text variants, screenshot composition briefs, hypothesis rationales) run on LLM and image-model APIs you connect via your own keys at Starter and Pro. Teams can use managed AI, your keys, or a mix.
- API keys are encrypted at rest with workspace-scoped envelope encryption.
- Keys are never logged, never written to telemetry, and never visible in plaintext after entry.
- You can rotate or revoke any key from Workspace Settings → AI Model. Revocation takes effect on the next generative request; in-flight requests complete on the previous key.
- Token and request costs incurred on your keys are billed by the model provider directly to you. ASOLOOP does not rebill or mark up third-party model usage.
4. Bounded AI commitments
LiveBounded AI is an architectural commitment, not a marketing claim. Three mechanisms enforce it on every generative output.
- AI evidence trail.Every LLM-rendered surface keeps its deterministic evidence in view — the data the model reasoned from stays visible beside the text, source-traced and revocable. You verify the claim; you don’t just trust it.
- Claim-safety validator. A mandatory gate runs before every generative output reaches you. Un-sourced revenue claims, regulated-category claims without evidence, and point-estimate revenue projections are rejected; deterministic-template fallback fires when LLM output is rejected.
- Signal traceability and revocation. Every signal ASOLOOP writes traces to a source experiment. You can inspect any signal, see which experiment contributed it, and revoke it within a 7-day window. Revoked signals immediately stop influencing future recommendations.
5. Access controls and roles
Live- Workspace roles: Owner / Member / Billing / Viewer — every role works experiments and signals; billing, membership, credentials and app deletion stay owner- or billing-scoped. Every member sees every app in the workspace (per-app scoping is on the Enterprise roadmap).
- Two-factor authentication: available at all tiers via TOTP authenticator apps; required for Owners at Teams.
- SSO and SAML: available at Teams; SCIM user provisioning available at Teams.
- Rights Administrator (Teams-only): workspace-level role authorized to approve regulated-claim attestations (healthtech, fintech, gambling, children’s apps). Required for any generative output that triggers a regulated-claim policy.
- Session management: idle-session expiration configurable at Teams (default 30 days); device-list visible in Workspace Settings.
6. Audit trail and reversibility
Live- Every signal write is logged with source experiment, contributing actor, and timestamp.
- Every action with material effect (apply-winner, suspend experiment, revoke signal, edit Project Rule, change Workspace Settings) is recorded in the action log with actor + timestamp.
- Every action has an undo path. Suspending an experiment, revoking a signal, or turning Autopilot off takes effect on the next cycle.
- Audit log export— CSV / JSON export of the action log over arbitrary date range, available at Teams.
7. Subprocessors
LiveASOLOOP engages the following subprocessors to operate the Service. A current list is maintained here; subscribe via it@asoloop.com to receive 30-day prior notice of new subprocessors at Teams.
| Subprocessor | Purpose | Region |
|---|---|---|
| Stripe | Subscription billing, payment processing, invoicing Operator billing contact, payment method (tokenized), subscription metadata | US (global processing) |
| Resend | Transactional email delivery (signup, billing, lifecycle, alerts) Operator email address, message body, delivery telemetry | US |
| AppsFlyer / Adjust / Branch / Firebase | MMP read-only ingestion for ARPU + install-to-paid + lifespan inputs Operator-authorized MMP credentials; aggregated install/revenue metrics | Per MMP provider (operator-controlled connection) |
| Apple App Store Connect API · Google Play Console API | Read-only metadata + experiment-result ingestion via operator-authorized credentials Operator-authorized API tokens; app metadata; PPO/CPP/SLE/CSL experiment results | Per platform (Apple US/EU; Google US/EU) |
| Cloudflare | DNS, CDN/edge network, and DDoS mitigation for the marketing site and application domains Domain routing metadata; edge request logs (IP, user agent) used for security filtering only | Global edge network (US-based origin) |
| Fly.io | Application hosting — API, background worker, and live-connect runner compute Customer Data in transit through the application layer; no data-at-rest storage on this subprocessor | US (multi-region available at Teams per V1.1 Wave 6) |
| Neon | Primary managed Postgres database — application state and Customer Data at rest All Customer Data at rest (AES-256 encrypted) | US (multi-region available at Teams per V1.1 Wave 6) |
| Google LLC (Google Analytics 4 / Google Tag Manager) | Marketing-site usage analytics — page views, navigation, conversion funnels Anonymized IP, page path, referrer, viewport; behavioral cookies (`_ga` / `_gid`) gated behind Consent Mode v2 — denied by default until explicit visitor opt-in | US (global processing) |
8. Compliance roadmap
Honest framing: what we honor today, what we’re actively building, and what we don’t pursue.
GDPR data subject rights
LiveAccess, rectification, erasure, portability, and objection rights honored today. Requests routed to it@asoloop.com; responded within 30 days.
SOC 2 Type II
In progressCurrently in pre-audit gap-closure. We are not making the claim of SOC 2 compliance until the audit completes. Letter of engagement available on request for Teams procurement.
Multi-region data residency
RoadmapEU and APAC data-residency regions are on the V1.1 Wave 6 roadmap (Teams tier). US-only today.
HIPAA, PCI DSS, ISO 27001
RoadmapNot currently pursued. ASOLOOPis not designed to process protected health information (PHI), cardholder data (PAN), or children’s personal information; operators in regulated categories should keep this scope outside the Service. That narrow data posture is deliberate — it is what makes the Service safe to run on regulated-vertical apps.
9. Vulnerability disclosure
LiveFound a security issue? Report it to it@asoloop.com with subject line [security]. We acknowledge receipt within 2 business days and target a triage decision within 7 days.
We commit to a 90-day disclosure window for confirmed vulnerabilities; coordinated disclosure timelines are negotiable on request. We do not currently run a paid bug bounty program; Hall-of-Fame credit is available with researcher consent.
10. Incident response
Live- 24-hour internal triage from incident detection.
- 72-hour customer notification on confirmed personal-data breaches per GDPR Article 33.
- Post-incident report (root cause, customer impact, remediation, preventive measures) issued within 14 business days of resolution.
- Public status page is on the V1 GA roadmap; in the interim, incident communications go via email to Workspace Owners.
11. Security contact
Vulnerability reports, security questionnaires, and procurement-review requests: it@asoloop.com (subject line [security]). For Teams security-questionnaire intake, attach SIG-Lite or your standard form; we respond within 5 business days.
See also: Privacy Policy · DPA · Terms of Service