Security · Trust · Compliance

How we handle your data and your AI keys.

Specific commitments, named subprocessors, and an honest distinction between what we ship today, what we're building, and what we don't pursue. Built for teams that have to defend a tool choice through procurement and security review.

Last updated: 2026-05-22

Status legend

Each commitment below carries one of three flags so you know exactly what is true today versus on the roadmap.

LiveIn progressRoadmap

1. Data isolation

Live

Customer Data is partitioned per Workspace at the database layer. Per-app evidence libraries are scoped per-Workspace; signals from one Operator’s app do not feed another Operator’s recommendations. There is no global learning model, and no cross-Operator embedding pool that would create signal leakage.

Workspace boundaries are enforced at every API endpoint and every algorithm-layer read path. Cross-Workspace reads are not possible without an explicit Teams parent-child relationship configured by ASOLOOP Operations.

2. Encryption

Live
  • In transit: TLS 1.2 minimum (TLS 1.3 preferred) for all traffic between client, marketing site, application, API, and subprocessors. HSTS enabled on all public domains.
  • At rest: AES-256 encryption on the primary database, object storage, and backups. Encryption keys managed by the cloud-provider KMS with workspace-scoped envelope encryption for sensitive fields (BYOK API keys, MMP credentials).
  • Key rotation: Provider-managed master keys rotate per provider policy; workspace data-encryption keys rotate on credential rotation events.

3. Connect Your AI Model (BYOK key handling)

Live

Generative surfaces in ASOLOOP (text variants, screenshot composition briefs, hypothesis rationales) run on LLM and image-model APIs you connect via your own keys at Starter and Pro. Teams can use managed AI, your keys, or a mix.

  • API keys are encrypted at rest with workspace-scoped envelope encryption.
  • Keys are never logged, never written to telemetry, and never visible in plaintext after entry.
  • You can rotate or revoke any key from Workspace Settings → AI Model. Revocation takes effect on the next generative request; in-flight requests complete on the previous key.
  • Token and request costs incurred on your keys are billed by the model provider directly to you. ASOLOOP does not rebill or mark up third-party model usage.

4. Bounded AI commitments

Live

Bounded AI is an architectural commitment, not a marketing claim. Three mechanisms enforce it on every generative output.

  • AI evidence trail.Every LLM-rendered surface keeps its deterministic evidence in view — the data the model reasoned from stays visible beside the text, source-traced and revocable. You verify the claim; you don’t just trust it.
  • Claim-safety validator. A mandatory gate runs before every generative output reaches you. Un-sourced revenue claims, regulated-category claims without evidence, and point-estimate revenue projections are rejected; deterministic-template fallback fires when LLM output is rejected.
  • Signal traceability and revocation. Every signal ASOLOOP writes traces to a source experiment. You can inspect any signal, see which experiment contributed it, and revoke it within a 7-day window. Revoked signals immediately stop influencing future recommendations.

5. Access controls and roles

Live
  • Workspace roles: Owner / Member / Billing / Viewer — every role works experiments and signals; billing, membership, credentials and app deletion stay owner- or billing-scoped. Every member sees every app in the workspace (per-app scoping is on the Enterprise roadmap).
  • Two-factor authentication: available at all tiers via TOTP authenticator apps; required for Owners at Teams.
  • SSO and SAML: available at Teams; SCIM user provisioning available at Teams.
  • Rights Administrator (Teams-only): workspace-level role authorized to approve regulated-claim attestations (healthtech, fintech, gambling, children’s apps). Required for any generative output that triggers a regulated-claim policy.
  • Session management: idle-session expiration configurable at Teams (default 30 days); device-list visible in Workspace Settings.

6. Audit trail and reversibility

Live
  • Every signal write is logged with source experiment, contributing actor, and timestamp.
  • Every action with material effect (apply-winner, suspend experiment, revoke signal, edit Project Rule, change Workspace Settings) is recorded in the action log with actor + timestamp.
  • Every action has an undo path. Suspending an experiment, revoking a signal, or turning Autopilot off takes effect on the next cycle.
  • Audit log export— CSV / JSON export of the action log over arbitrary date range, available at Teams.

7. Subprocessors

Live

ASOLOOP engages the following subprocessors to operate the Service. A current list is maintained here; subscribe via it@asoloop.com to receive 30-day prior notice of new subprocessors at Teams.

SubprocessorPurposeRegion
Stripe

Subscription billing, payment processing, invoicing

Operator billing contact, payment method (tokenized), subscription metadata

US (global processing)
Resend

Transactional email delivery (signup, billing, lifecycle, alerts)

Operator email address, message body, delivery telemetry

US
AppsFlyer / Adjust / Branch / Firebase

MMP read-only ingestion for ARPU + install-to-paid + lifespan inputs

Operator-authorized MMP credentials; aggregated install/revenue metrics

Per MMP provider (operator-controlled connection)
Apple App Store Connect API · Google Play Console API

Read-only metadata + experiment-result ingestion via operator-authorized credentials

Operator-authorized API tokens; app metadata; PPO/CPP/SLE/CSL experiment results

Per platform (Apple US/EU; Google US/EU)
Cloudflare

DNS, CDN/edge network, and DDoS mitigation for the marketing site and application domains

Domain routing metadata; edge request logs (IP, user agent) used for security filtering only

Global edge network (US-based origin)
Fly.io

Application hosting — API, background worker, and live-connect runner compute

Customer Data in transit through the application layer; no data-at-rest storage on this subprocessor

US (multi-region available at Teams per V1.1 Wave 6)
Neon

Primary managed Postgres database — application state and Customer Data at rest

All Customer Data at rest (AES-256 encrypted)

US (multi-region available at Teams per V1.1 Wave 6)
Google LLC (Google Analytics 4 / Google Tag Manager)

Marketing-site usage analytics — page views, navigation, conversion funnels

Anonymized IP, page path, referrer, viewport; behavioral cookies (`_ga` / `_gid`) gated behind Consent Mode v2 — denied by default until explicit visitor opt-in

US (global processing)

8. Compliance roadmap

Honest framing: what we honor today, what we’re actively building, and what we don’t pursue.

  • GDPR data subject rights

    Live

    Access, rectification, erasure, portability, and objection rights honored today. Requests routed to it@asoloop.com; responded within 30 days.

  • SOC 2 Type II

    In progress

    Currently in pre-audit gap-closure. We are not making the claim of SOC 2 compliance until the audit completes. Letter of engagement available on request for Teams procurement.

  • Multi-region data residency

    Roadmap

    EU and APAC data-residency regions are on the V1.1 Wave 6 roadmap (Teams tier). US-only today.

  • HIPAA, PCI DSS, ISO 27001

    Roadmap

    Not currently pursued. ASOLOOPis not designed to process protected health information (PHI), cardholder data (PAN), or children’s personal information; operators in regulated categories should keep this scope outside the Service. That narrow data posture is deliberate — it is what makes the Service safe to run on regulated-vertical apps.

9. Vulnerability disclosure

Live

Found a security issue? Report it to it@asoloop.com with subject line [security]. We acknowledge receipt within 2 business days and target a triage decision within 7 days.

We commit to a 90-day disclosure window for confirmed vulnerabilities; coordinated disclosure timelines are negotiable on request. We do not currently run a paid bug bounty program; Hall-of-Fame credit is available with researcher consent.

10. Incident response

Live
  • 24-hour internal triage from incident detection.
  • 72-hour customer notification on confirmed personal-data breaches per GDPR Article 33.
  • Post-incident report (root cause, customer impact, remediation, preventive measures) issued within 14 business days of resolution.
  • Public status page is on the V1 GA roadmap; in the interim, incident communications go via email to Workspace Owners.

11. Security contact

Vulnerability reports, security questionnaires, and procurement-review requests: it@asoloop.com (subject line [security]). For Teams security-questionnaire intake, attach SIG-Lite or your standard form; we respond within 5 business days.