Skip to main content
At Loops, we care deeply about the safety and security of our customers’ data and our systems. We welcome security and vulnerability reports as part of our commitment to providing the most secure product possible. Use this page for security vulnerability reports. For security reviews, procurement questionnaires, data residency questions, SOC 2, DPA, Data Privacy Framework (DPF), 2FA, MFA, SSO, or other compliance requests, start with these resources: If you need something that is not covered there, go to your Support page or email help@loops.so.

Making a report

If you’ve read this document and discovered an issue that you believe is in-scope, please email us at security@loops.so. Please include the following details:
  • A clear summary of the issue and its potential impact.
  • Detailed steps to reproduce the issue.
  • Relevant environmental details (browser, OS, version numbers, etc.).
  • Any proof-of-concept code that demonstrates the vulnerability, if available.
Additionally, we have a few meta requests:
  • No more than one report per email, with logical exceptions like the same finding in multiple places.
  • The email should contain the report directly. Do not attach the report as a PDF. Attachments for supporting information or files is fine.
  • Whether or not AI was used in the generation of your report. Knowing the model would be great as well.
  • Please avoid submitting large numbers of findings at once. Particularly if they are low or medium severity.
Our security team will review your report and keep you updated on our progress, requesting additional information or clarification when needed. We believe that vulnerability reporting creates a safer, better product for our customers. As such, we offer compensation for reports with a CVSS v4 score of 4 or higher, as determined by us.

Timelines

We’ll get back to you within a few days to acknowledge your report.

What we’re most interested in

  • Authentication bypass and privilege escalation.
  • Exposure of personally identifiable information (PII).
  • Unauthenticated access to user data (outside of intentionally public data).

In scope

Out of scope

  • Automated scanning (including AI agents broadly probing systems for issues).
  • Social engineering.
  • Denial of Service attacks.
  • Attacks that need physical access to someone’s computer.
  • Theoretical attacks you can’t actually exploit.
  • Man-in-the-middle attacks.
  • Clickjacking or UI redress attacks.
  • CSV injection (unless it can harm non-Loops users).
  • HTML injection (unless it can harm non-Loops users).
  • Missing security headers, weak TLS cipher suites, or DNS setup issues. We might find these informative, but they probably won’t earn a bounty.

Please be considerate while investigating

  • Only test with your own account (or get permission from the account owner first).
  • Don’t modify, delete, or store private data that isn’t yours.
  • Avoid anything that might break or slow down our services.
  • If you get remote access to our systems, don’t try to expand or elevate your access.

A note on AI use

We understand and expect that AI tools will be used in the generation, testing, and submission of reports. We use them too. However, we also expect there is a human reviewing and verifying all work. When you submit a report to us, you can expect that a human reads, reviews, and personally responds to you. Please ensure that all claims can be easily substantiated by a human. Generative AI has resulted in a significant increase in the volume of received reports at all quality levels. We want to talk to you, not your AI agent, as we discuss a report. Researchers who disregard these policies may be banned from participating in our program.

Safe harbor

Any activities conducted in a manner consistent with this document will be considered authorized and Loops will not initiate legal action against you.
Last modified on September 10, 2026