Security at Loopvolt

Last updated:

Protecting your data is core to everything we build. Here is an overview of the measures we take to keep your account and information safe. Questions? Contact us at [email protected].

Data Encryption

Encryption in transit

All data transmitted between your browser and Loopvolt is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and redirect any unencrypted traffic automatically.

Encryption at rest

Sensitive data stored in our databases is encrypted at rest using AES-256. This includes your account credentials, connected account tokens, and any personal information you provide.

Access Controls

Authentication

Loopvolt uses industry-standard OAuth 2.0 to connect your LinkedIn account. We never store your LinkedIn password — only a limited-scope access token that you can revoke at any time from your LinkedIn settings.

Least-privilege access

We request only the minimum permissions needed to provide the Service. Internal access to production systems is role-based and requires multi-factor authentication for all engineers.

Session management

User sessions are managed with short-lived, cryptographically signed tokens stored in HTTP-only cookies. Sessions expire automatically after a period of inactivity.

Infrastructure

Cloud provider

Loopvolt is hosted on Vercel and AWS, both of which maintain SOC 2 Type II and ISO 27001 certifications. Our infrastructure benefits from their extensive physical and network security controls.

Network security

Our production environment is isolated within a private network. All public-facing services sit behind a Web Application Firewall (WAF) and are protected against common threats including SQL injection, XSS, and DDoS attacks.

Backups

Database backups are taken automatically on a daily basis and retained for 30 days. Backups are encrypted and stored in a separate geographic region from production data.

Vulnerability Management

Dependency monitoring

We continuously monitor our dependencies for known vulnerabilities using automated tooling. Critical security patches are applied within 24 hours of disclosure.

Code review

All code changes undergo peer review before being merged into production. Security-sensitive changes require an additional review from a senior engineer.

Responsible disclosure

If you discover a security vulnerability in Loopvolt, please report it to [email protected]. We ask that you give us a reasonable amount of time to investigate and address the issue before public disclosure. We do not pursue legal action against researchers who follow responsible disclosure principles.

Compliance

GDPR

We are committed to complying with the General Data Protection Regulation (GDPR) for users in the European Economic Area. You have the right to access, correct, export, and delete your personal data at any time. See our Privacy Policy for full details.

CCPA

California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to opt out of the sale of personal information. We do not sell personal data.

Payment security

Loopvolt does not store credit or debit card details. All payment processing is handled by Stripe, which is PCI DSS Level 1 certified — the highest level of certification available in the payments industry.

Contact Our Security Team

Get in touch

For security concerns, vulnerability reports, or questions about our security practices, please contact us at [email protected]. For general privacy questions, see our Privacy Policy or reach out at [email protected].