ClosedLoop AI · Trust Center

Closedloop Trust Center

Trust center

ClosedLoop AI maintains a public trust center documenting SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and FedRAMP compliance.

Product IntelligenceCustomer FeedbackVoice of CustomerProduct ManagementAgentic AIMCPSaaS analyticsA2ASCIMProduct Discovery
Trust center:

Certifications & Compliance

SOC 2 Type IIISO 27001PCI DSSHIPAAFedRAMP

Source

Trust Center

Raw ↑
generated: '2026-08-30'
method: searched
source: https://closedloop.sh/pricing, https://closedloop.sh/docs/guides/vendor-listing,
  https://trust.closedloop.sh
note: >-
  probe-security-programs.py returned trust=none because trust.closedloop.sh renders entirely
  client-side and served no readable certification text to an anonymous fetch. It IS a real trust
  surface -- this file records what the provider publishes in machine-readable-adjacent form
  elsewhere on its own site, with each claim's source and status.
trust_center:
  url: https://trust.closedloop.sh
  status: 200
  readable: false
  readable_detail: >-
    Returns a Next.js SPA titled "Trust Vault" with no server-rendered content. No certification
    names, no document list and no report-request flow were readable without executing JavaScript.
    Recorded honestly: the page exists and 200s, but a machine cannot read it.
  linked_from_site: not-found
  linked_from_site_detail: >-
    No link to trust.closedloop.sh was found from the marketing navigation, the docs, or the
    vendor-listing guide. The subdomain was discovered by probe, not by following a first-party
    link.
certifications:
- name: SOC 2 Type II
  claimed: true
  source: https://closedloop.sh/pricing
  source_status: 200
  evidence: >-
    Listed as "Included" on Free, Pay as you go and Enterprise in the published plan-comparison
    table, and again in the "On every plan" summary block.
  report_public: false
  report_note: The attestation report itself is not published; no request flow was readable.
- name: ISO 27001
  claimed: false
- name: PCI DSS
  claimed: false
  note: Not applicable -- ClosedLoop AI processes no cardholder data.
- name: HIPAA
  claimed: false
- name: FedRAMP
  claimed: false
privacy_program:
  vendor_listing_page: https://closedloop.sh/docs/guides/vendor-listing
  vendor_listing_status: 200
  vendor_listing_note: >-
    A genuinely unusual artifact: a documentation page written FOR the buyer's security, privacy or
    procurement team, giving the legal entity, registered address, processor role, contacts, data
    categories and every policy link in a copy-paste block. Most providers make a buyer assemble
    this from a PDF.
  legal_entity: ClosedLoop Labs LLC, doing business as ClosedLoop AI
  registered_address: 7901 4th St N Ste 300, St. Petersburg, FL 33702, United States
  role: Data processor / vendor
  privacy_contact: dpo@closedloop.sh
  support_contact: support@closedloop.sh
  documents:
  - name: Privacy Policy
    url: https://closedloop.sh/privacy
    status: 200
  - name: Data Processing Agreement
    url: https://closedloop.sh/dpa
    status: 200
  - name: Subprocessors
    url: https://closedloop.sh/subprocessors
    status: 200
  - name: AI Terms
    url: https://closedloop.sh/ai-terms
    status: 200
  - name: Terms of Service
    url: https://closedloop.sh/terms
    status: 200
data_residency:
  regions: [us, eu]
  selection: chosen during onboarding, per workspace
  guarantee: >-
    "During normal operations, EU workspace data does not leave the EU region." Carried through
    every surface -- app (eu.app), REST API (eu.api), MCP (eu.mcp), SCIM and SSO all have EU
    equivalents.
  source: https://closedloop.sh/docs/guides/vendor-listing
access_posture:
  read_only_connections: true
  read_only_source: https://closedloop.sh/pricing
  read_only_detail: >-
    "Read-only connections" is listed as an on-every-plan property, and the /v1 API is GET-only,
    which corroborates it from the contract side rather than from marketing alone.
enterprise_controls:
  sso: [Okta OIDC, Google Workspace SAML, Microsoft Entra ID SAML]
  provisioning: SCIM 2.0 (Okta, Entra ID) with Group Push and role entitlements
  offboarding: Global Token Revocation endpoint (Okta Universal Logout)
  plan_gate: Enterprise
  cross_ref: conformance/closedloop-conformance.yml
vulnerability_disclosure:
  published: false
  probes:
  - url: https://closedloop.sh/.well-known/security.txt
    status: 404
  - url: https://api.closedloop.sh/.well-known/security.txt
    status: 404
  - url: https://docs.closedloop.sh/.well-known/security.txt
    status: 404
  - url: https://closedloop.sh/security.txt
    status: 404
  - url: https://closedloop.sh/security
    status: 404
  detail: >-
    No security.txt on any host, no /security page, no bug-bounty program found on HackerOne,
    Bugcrowd or Intigriti, and no disclosure policy in the docs. A researcher who finds a
    vulnerability has no published channel other than support@closedloop.sh. This is the clearest
    single gap in an otherwise strong security posture, and it is cheap for the provider to close.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/closedloop-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.