ClosedLoop AI · Trust Center
Closedloop Trust Center
Trust center
ClosedLoop AI maintains a public trust center documenting SOC 2 Type II, ISO 27001, PCI DSS, HIPAA, and FedRAMP compliance.
Product IntelligenceCustomer FeedbackVoice of CustomerProduct ManagementAgentic AIMCPSaaS analyticsA2ASCIMProduct Discovery
Certifications & Compliance
SOC 2 Type IIISO 27001PCI DSSHIPAAFedRAMP
Source
Trust Center
generated: '2026-08-30'
method: searched
source: https://closedloop.sh/pricing, https://closedloop.sh/docs/guides/vendor-listing,
https://trust.closedloop.sh
note: >-
probe-security-programs.py returned trust=none because trust.closedloop.sh renders entirely
client-side and served no readable certification text to an anonymous fetch. It IS a real trust
surface -- this file records what the provider publishes in machine-readable-adjacent form
elsewhere on its own site, with each claim's source and status.
trust_center:
url: https://trust.closedloop.sh
status: 200
readable: false
readable_detail: >-
Returns a Next.js SPA titled "Trust Vault" with no server-rendered content. No certification
names, no document list and no report-request flow were readable without executing JavaScript.
Recorded honestly: the page exists and 200s, but a machine cannot read it.
linked_from_site: not-found
linked_from_site_detail: >-
No link to trust.closedloop.sh was found from the marketing navigation, the docs, or the
vendor-listing guide. The subdomain was discovered by probe, not by following a first-party
link.
certifications:
- name: SOC 2 Type II
claimed: true
source: https://closedloop.sh/pricing
source_status: 200
evidence: >-
Listed as "Included" on Free, Pay as you go and Enterprise in the published plan-comparison
table, and again in the "On every plan" summary block.
report_public: false
report_note: The attestation report itself is not published; no request flow was readable.
- name: ISO 27001
claimed: false
- name: PCI DSS
claimed: false
note: Not applicable -- ClosedLoop AI processes no cardholder data.
- name: HIPAA
claimed: false
- name: FedRAMP
claimed: false
privacy_program:
vendor_listing_page: https://closedloop.sh/docs/guides/vendor-listing
vendor_listing_status: 200
vendor_listing_note: >-
A genuinely unusual artifact: a documentation page written FOR the buyer's security, privacy or
procurement team, giving the legal entity, registered address, processor role, contacts, data
categories and every policy link in a copy-paste block. Most providers make a buyer assemble
this from a PDF.
legal_entity: ClosedLoop Labs LLC, doing business as ClosedLoop AI
registered_address: 7901 4th St N Ste 300, St. Petersburg, FL 33702, United States
role: Data processor / vendor
privacy_contact: dpo@closedloop.sh
support_contact: support@closedloop.sh
documents:
- name: Privacy Policy
url: https://closedloop.sh/privacy
status: 200
- name: Data Processing Agreement
url: https://closedloop.sh/dpa
status: 200
- name: Subprocessors
url: https://closedloop.sh/subprocessors
status: 200
- name: AI Terms
url: https://closedloop.sh/ai-terms
status: 200
- name: Terms of Service
url: https://closedloop.sh/terms
status: 200
data_residency:
regions: [us, eu]
selection: chosen during onboarding, per workspace
guarantee: >-
"During normal operations, EU workspace data does not leave the EU region." Carried through
every surface -- app (eu.app), REST API (eu.api), MCP (eu.mcp), SCIM and SSO all have EU
equivalents.
source: https://closedloop.sh/docs/guides/vendor-listing
access_posture:
read_only_connections: true
read_only_source: https://closedloop.sh/pricing
read_only_detail: >-
"Read-only connections" is listed as an on-every-plan property, and the /v1 API is GET-only,
which corroborates it from the contract side rather than from marketing alone.
enterprise_controls:
sso: [Okta OIDC, Google Workspace SAML, Microsoft Entra ID SAML]
provisioning: SCIM 2.0 (Okta, Entra ID) with Group Push and role entitlements
offboarding: Global Token Revocation endpoint (Okta Universal Logout)
plan_gate: Enterprise
cross_ref: conformance/closedloop-conformance.yml
vulnerability_disclosure:
published: false
probes:
- url: https://closedloop.sh/.well-known/security.txt
status: 404
- url: https://api.closedloop.sh/.well-known/security.txt
status: 404
- url: https://docs.closedloop.sh/.well-known/security.txt
status: 404
- url: https://closedloop.sh/security.txt
status: 404
- url: https://closedloop.sh/security
status: 404
detail: >-
No security.txt on any host, no /security page, no bug-bounty program found on HackerOne,
Bugcrowd or Intigriti, and no disclosure policy in the docs. A researcher who finds a
vulnerability has no published channel other than support@closedloop.sh. This is the clearest
single gap in an otherwise strong security posture, and it is cheap for the provider to close.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/closedloop-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.