Daloopa · Trust Center
Daloopa Trust Center
Trust center
Daloopa operates a Vanta-hosted trust center at trust.daloopa.com. Its EXISTENCE is verified; its CONTENTS are not publicly machine-readable. This artifact records exactly that boundary and names no certification that could not be read from a public source.
Daloopa maintains a public trust center covering its security and compliance posture.
financial-datafundamental-datamarket-datainvestment-researchequity-researchsec-filingsearningsfintechmcpagent-nativeagent-skillswebhooksdata-warehouse
Certifications & Compliance
Source
Trust Center
generated: '2026-08-11'
method: probed
source: https://trust.daloopa.com/
description: >-
Daloopa operates a Vanta-hosted trust center at trust.daloopa.com. Its EXISTENCE is verified; its
CONTENTS are not publicly machine-readable. This artifact records exactly that boundary and names no
certification that could not be read from a public source.
trust_center:
published: true
url: https://trust.daloopa.com/
vendor: Vanta
vendor_evidence: >-
Served HTML contains a `vanta-entry-loader` element and 36 references to vanta.com asset hosts. Page
title is "daloopa.com Trust Center".
x-evidence:
fetched: '2026-08-11'
probes:
- {url: 'https://trust.daloopa.com/', http_status: 200, content_type: 'text/html', note: 'JS-rendered SPA shell; no certification text in the served markup'}
- {url: 'https://trust.daloopa.com/api/trustPage', http_status: 200, content_type: 'text/html', note: 'SPA catch-all, not JSON — a miss'}
- {url: 'https://trust.daloopa.com/api/v1/trust-center', http_status: 200, content_type: 'text/html', note: 'SPA catch-all, not JSON — a miss'}
- {url: 'https://trust.daloopa.com/data.json', http_status: 200, content_type: 'text/html', note: 'SPA catch-all, not JSON — a miss'}
- {url: 'https://api.vanta.com/v1/trust-pages/daloopa.com', http_status: 401, content_type: 'application/json', note: 'authenticated endpoint'}
- {url: 'https://daloopa.com/privacy-policy', http_status: 200, note: 'GDPR referenced; no SOC 2 / ISO 27001 named'}
- {url: 'https://daloopa.com/terms-of-use', http_status: 200, note: 'no certification named'}
- {url: 'https://daloopa.com/products/api', http_status: 200, note: 'no certification named'}
- {url: 'https://docs.daloopa.com/docs/excel-add-in-security-and-architecture', http_status: 200, note: 'IT/infosec review page; no certification named in the markdown'}
certifications: []
certifications_note: >-
DELIBERATELY EMPTY. Every host and path above was probed and no named certification (SOC 2, ISO 27001,
PCI DSS, HIPAA, FedRAMP) could be read from any public, unauthenticated source. A Vanta trust center of
this kind normally lists frameworks and gates the underlying reports behind an NDA request form, so it
is likely certifications exist — but "likely" is not evidence, and none are recorded here. No
`type: Compliance` pointer is emitted in apis.yml for the same reason.
If Daloopa wants this reflected, the fix on their side is small: name the frameworks in server-rendered
HTML, or link the trust center from a /.well-known/security.txt.
published_security_material:
- name: Excel Add-In Security and Architecture
url: https://docs.daloopa.com/docs/excel-add-in-security-and-architecture
note: >-
A dedicated page describing how the add-in is built, what it can and cannot access in a desktop
environment, and the controls governing its behavior — written explicitly to give customer IT and
infosec teams what they need for approval. A genuinely mature artifact for an Office add-in.
- name: Privacy and Data Collection Disclosure for MCP Access
url: https://docs.daloopa.com/docs/daloopa-privacy-and-data-collection-disclosure-for-mcp-access
note: >-
A separate privacy disclosure written specifically for the MCP surface. Very few providers in the
catalog publish an agent-surface-specific privacy disclosure at all.
- name: Single Sign-On
url: https://docs.daloopa.com/docs/single-sign-on
note: Microsoft Entra (Azure AD) SSO integration guide.
- name: Privacy Policy
url: https://daloopa.com/privacy-policy
- name: Terms of Use
url: https://daloopa.com/terms-of-use
api_security_controls:
key_rotation: Published six-month API key rotation cycle.
ip_allowlisting: Available on request — restricts API access to pre-approved addresses.
source: https://docs.daloopa.com/docs/api-authentication
vulnerability_disclosure:
published: false
security_txt: false
bug_bounty: null
security_contact: null
note: >-
No security.txt on any of the five hosts, no published vulnerability disclosure or responsible
disclosure policy, and no HackerOne/Bugcrowd/Intigriti program found. No dedicated security@ address is
published; the only contact addresses are sales@, support@ and api-support@daloopa.com. No
VulnerabilityDisclosure artifact or `type: Security` pointer is emitted, because there is no program to
point at.
cross_links:
domain_security: security/daloopa-domain-security.yml
well_known: well-known/daloopa-well-known.yml
conformance: conformance/daloopa-conformance.yml
authentication: authentication/daloopa-authentication.yml