Daloopa · Trust Center

Daloopa Trust Center

Trust center

Daloopa operates a Vanta-hosted trust center at trust.daloopa.com. Its EXISTENCE is verified; its CONTENTS are not publicly machine-readable. This artifact records exactly that boundary and names no certification that could not be read from a public source.

Daloopa maintains a public trust center covering its security and compliance posture.

financial-datafundamental-datamarket-datainvestment-researchequity-researchsec-filingsearningsfintechmcpagent-nativeagent-skillswebhooksdata-warehouse
Trust center:

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-08-11'
method: probed
source: https://trust.daloopa.com/
description: >-
  Daloopa operates a Vanta-hosted trust center at trust.daloopa.com. Its EXISTENCE is verified; its
  CONTENTS are not publicly machine-readable. This artifact records exactly that boundary and names no
  certification that could not be read from a public source.

trust_center:
  published: true
  url: https://trust.daloopa.com/
  vendor: Vanta
  vendor_evidence: >-
    Served HTML contains a `vanta-entry-loader` element and 36 references to vanta.com asset hosts. Page
    title is "daloopa.com Trust Center".

x-evidence:
  fetched: '2026-08-11'
  probes:
  - {url: 'https://trust.daloopa.com/', http_status: 200, content_type: 'text/html', note: 'JS-rendered SPA shell; no certification text in the served markup'}
  - {url: 'https://trust.daloopa.com/api/trustPage', http_status: 200, content_type: 'text/html', note: 'SPA catch-all, not JSON — a miss'}
  - {url: 'https://trust.daloopa.com/api/v1/trust-center', http_status: 200, content_type: 'text/html', note: 'SPA catch-all, not JSON — a miss'}
  - {url: 'https://trust.daloopa.com/data.json', http_status: 200, content_type: 'text/html', note: 'SPA catch-all, not JSON — a miss'}
  - {url: 'https://api.vanta.com/v1/trust-pages/daloopa.com', http_status: 401, content_type: 'application/json', note: 'authenticated endpoint'}
  - {url: 'https://daloopa.com/privacy-policy', http_status: 200, note: 'GDPR referenced; no SOC 2 / ISO 27001 named'}
  - {url: 'https://daloopa.com/terms-of-use', http_status: 200, note: 'no certification named'}
  - {url: 'https://daloopa.com/products/api', http_status: 200, note: 'no certification named'}
  - {url: 'https://docs.daloopa.com/docs/excel-add-in-security-and-architecture', http_status: 200, note: 'IT/infosec review page; no certification named in the markdown'}

certifications: []
certifications_note: >-
  DELIBERATELY EMPTY. Every host and path above was probed and no named certification (SOC 2, ISO 27001,
  PCI DSS, HIPAA, FedRAMP) could be read from any public, unauthenticated source. A Vanta trust center of
  this kind normally lists frameworks and gates the underlying reports behind an NDA request form, so it
  is likely certifications exist — but "likely" is not evidence, and none are recorded here. No
  `type: Compliance` pointer is emitted in apis.yml for the same reason.
  If Daloopa wants this reflected, the fix on their side is small: name the frameworks in server-rendered
  HTML, or link the trust center from a /.well-known/security.txt.

published_security_material:
- name: Excel Add-In Security and Architecture
  url: https://docs.daloopa.com/docs/excel-add-in-security-and-architecture
  note: >-
    A dedicated page describing how the add-in is built, what it can and cannot access in a desktop
    environment, and the controls governing its behavior — written explicitly to give customer IT and
    infosec teams what they need for approval. A genuinely mature artifact for an Office add-in.
- name: Privacy and Data Collection Disclosure for MCP Access
  url: https://docs.daloopa.com/docs/daloopa-privacy-and-data-collection-disclosure-for-mcp-access
  note: >-
    A separate privacy disclosure written specifically for the MCP surface. Very few providers in the
    catalog publish an agent-surface-specific privacy disclosure at all.
- name: Single Sign-On
  url: https://docs.daloopa.com/docs/single-sign-on
  note: Microsoft Entra (Azure AD) SSO integration guide.
- name: Privacy Policy
  url: https://daloopa.com/privacy-policy
- name: Terms of Use
  url: https://daloopa.com/terms-of-use

api_security_controls:
  key_rotation: Published six-month API key rotation cycle.
  ip_allowlisting: Available on request — restricts API access to pre-approved addresses.
  source: https://docs.daloopa.com/docs/api-authentication

vulnerability_disclosure:
  published: false
  security_txt: false
  bug_bounty: null
  security_contact: null
  note: >-
    No security.txt on any of the five hosts, no published vulnerability disclosure or responsible
    disclosure policy, and no HackerOne/Bugcrowd/Intigriti program found. No dedicated security@ address is
    published; the only contact addresses are sales@, support@ and api-support@daloopa.com. No
    VulnerabilityDisclosure artifact or `type: Security` pointer is emitted, because there is no program to
    point at.

cross_links:
  domain_security: security/daloopa-domain-security.yml
  well_known: well-known/daloopa-well-known.yml
  conformance: conformance/daloopa-conformance.yml
  authentication: authentication/daloopa-authentication.yml