Skip to content
LogicLoop LLC ← Back to site

Legal

Security Policy

Last updated: July 30, 2026

The short version. We work inside your systems rather than copying your data out of them. Access is scoped, credentialed properly, and removed when the job ends. We are a small independent practice and hold no security certifications — this page describes what we actually do, so you can judge it honestly.

1. Scope

This policy covers how we handle access, credentials, and data belonging to clients and visitors, and how to report a security problem to us. It supports the commitments in our Privacy Policy and Data Processing Agreement.

2. How we approach it

  • Work in place, don't take copies. Automations are built inside your own accounts. The fewer copies of your data that exist, the smaller the problem if something goes wrong.
  • Least privilege. We ask for the narrowest access that will do the job, for the shortest time.
  • Your accounts, your ownership. Everything we build lives under your control. You are never locked out of, or dependent on, our accounts.
  • Assume the worst case. Builds are designed so a failure is visible and recoverable, not silent.

3. Access control

  • Named individual accounts — never shared logins.
  • Multi-factor authentication enabled everywhere it's supported.
  • Scoped service accounts, API keys, or delegated access in preference to a person's personal login. Where a platform only supports personal accounts, we say so and agree an approach with you.
  • Access is reviewed at project milestones and revoked at the end of the engagement. You can revoke it yourself at any moment without asking us.
  • We'll give you a written list of every access we hold on request.

4. How to share credentials with us

Please don't email us passwords or API keys, and don't send them by SMS or chat. Instead:

  • Invite us as a user to the platform, with the role we need — this is always the best option.
  • Or share through your password manager's secure sharing feature.
  • Or use a one-time secret link that expires after viewing.

On our side, credentials go into a password manager or secrets store — never into source code, spreadsheets, notes, tickets, or plain email. Secrets referenced by automations are held in the platform's own secrets manager, not hard-coded.

5. Handling your data

  • Data in transit is protected with current TLS.
  • Devices used for client work have full-disk encryption, automatic screen lock, maintained OS and security updates, and current endpoint protection.
  • We avoid extracts. Where a test dataset is genuinely needed, we prefer anonymised or synthetic data, keep any real extract minimal, and delete it when the work is done.
  • Client data is never stored on personal or unmanaged cloud storage.
  • We don't use client data to train AI models, and we don't paste it into consumer AI tools — see our AI Usage Policy.

6. Security of what we build

  • Automations are tested against real conditions before switch-over, and run alongside the existing process until they hold up.
  • We build in logging and failure alerts so a broken workflow is noticed rather than silently dropping work.
  • Least-privilege applies to the automation itself — a workflow gets only the permissions it needs.
  • Handover documentation includes what the automation can access and how to switch it off.

7. Sub-processors and vendors

We keep our vendor list short and prefer established providers with a clear security posture and honest data-handling terms. Vendors handling client Personal Data are treated as Sub-processors under the DPA, and we'll name the ones relevant to your engagement.

8. Incident response

If we become aware of a security incident affecting your data or systems, we will contain it, investigate, and notify you without undue delay and within seventy-two (72) hours of becoming aware. You'll get what we know, what we've done, and what we recommend — followed by updates and, once resolved, a written summary of cause and corrective action.

9. Continuity

Because your automations run in your own accounts, they keep running independently of us. Documentation is delivered to you as part of every project, specifically so your business isn't dependent on our availability. Our own working files and records are backed up.

10. Certifications — a straight answer

LogicLoop LLC does not currently hold SOC 2, ISO 27001, HIPAA, PCI-DSS, or any other formal security certification or attestation, and has not undergone a third-party security audit. We're an independent practice and we'd rather tell you that plainly than imply otherwise. This page describes real practices, not a certified programme.

If your procurement process requires a certified vendor, or your data falls under a regime like HIPAA or PCI-DSS, tell us early. We'll either agree appropriate safeguards in writing or tell you we're not the right fit.

11. Reporting a vulnerability

If you've found a security problem in this website or in something we built, please tell us: contact@logicloop.agency, with "Security" in the subject line.

Helpful to include: what you found, how to reproduce it, and what you think the impact is.

Our commitment. We'll acknowledge within three (3) business days, keep you updated, and credit you if you'd like. We will not pursue legal action against anyone who reports a genuine issue in good faith, provided you don't access or modify data that isn't yours, don't degrade the service, and give us reasonable time to fix it before publishing. We don't currently run a paid bug bounty.

12. Your part

Security is shared. Please keep multi-factor authentication on, remove our access when an engagement ends if we haven't already, review who has access to your platforms periodically, and tell us promptly if you suspect a compromise on your side that might touch shared systems.

Contact

Questions about this policy:

LogicLoop LLC
1805 Robin Ave
Fort Worth, TX 76164
contact@logicloop.agency
LogicLoop LLC

Business automation · Fort Worth, Texas

Services How it works FAQ About Contact

© 2026 LogicLoop LLC. All rights reserved. A Texas limited liability company.

Privacy Terms All legal