AutoLoopers
AutoLoopers
Get A Demo

Security

Last updated 4 Aug 2026

The short version

  • We work inside accounts that belong to you, with scoped access rather than full administrator rights.
  • Only people you have approved get that access, and you can revoke it at any moment without asking us.
  • Nothing of yours is copied onto our systems.
  • Every account we touch is protected by two factor authentication and managed in a password manager.

Why this page exists

Hiring someone to automate your operations means handing them access to the systems your business runs on. That is a real thing to be nervous about, and a page that answered it with logos and acronyms would be avoiding the question.

So this page says exactly what access we take, who has it, what happens to your information, and what we do not claim. If something here is not clear enough to act on, ask us and we will answer plainly.

How access works

We work inside your accounts, not copies of them. The systems we build live where your business already runs, so they stay yours whether or not we are still working together.

How it works
What we ask forScoped access, limited to what the build actually needs. Not blanket administrator rights by default.
Who grants itYou do. We cannot give ourselves access to anything.
Who can remove itYou can, at any time, without telling us first and without our involvement.
What happens if you doThe work stops. Nothing about revoking access damages what has already been built in your account.

If a piece of work genuinely needs a higher permission level, we ask for it, explain what it is for, and you decide. We would rather have that conversation than hold access we do not need.

Who gets access

Only people you have approved. Access is granted to named members of our team, and the client approves who those people are. It is not pooled, and it is not handed to whoever happens to be free that week.

On our side, every account we touch is:

  • Protected by two factor authentication
  • Held in a password manager, not in a spreadsheet, a message thread or somebody’s browser

What happens to your information

Nothing of yours is copied onto our systems. We do not take exports, we do not keep a shadow copy of your database, and we do not hold your customer records on our own infrastructure.

One distinction worth being precise about, because it is the honest version:

We do not use your information to train anything, and we do not reuse one client’s information for another client.

For how we handle information collected through this website, which is a separate question, see our Privacy Policy.

When an engagement ends

There is an offboarding step, and it runs whether the engagement ends on good terms or not.

  • Access is removed. You can also revoke it yourself at any point, before or after, without waiting for us.
  • The build stays with you. The configuration, the automations, the account setup and the written procedures are in your accounts and they remain yours.
  • Anything running on our infrastructure stops. That is the honest limit of what handover means, and the Terms of Service sets it out.

What we do not claim

We would rather be the company that tells you what it has not got.

  • We are not SOC 2 or ISO 27001 certified. We are a small team, and claiming a certification we do not hold would be a strange place to start a relationship built on access to your systems.
  • We do not run a bug bounty or a public penetration testing programme.
  • We will not tell you a system is perfectly secure. No one can, and the people who say it are the ones worth worrying about.

What we do offer is the thing that actually reduces your exposure: the systems are in your accounts, the access is scoped, and you can end it unilaterally at any moment.

Questions people actually ask

Can you see everything in our account?

No, not by default. We ask for scoped access limited to what the build needs. If a task needs more, we ask you for it and tell you why.

What if we want to stop right now?

Revoke the access. You do not need our cooperation, our notice period or our permission, and nothing already built in your account is affected.

Do you store our customer data?

No. Nothing of yours is copied onto our systems. Where a workflow we operate has to process information as it runs, it passes through and is not retained, and we tell you in advance which parts those are.

Who exactly will have access?

Named people on our team, approved by you. If that list needs to change during an engagement, we ask you first.

What happens if you are breached?

We tell you, quickly, and we tell you what we know rather than waiting until the picture is complete. Access we hold to your systems can be revoked by you the moment you hear, which is the single most useful thing either of us can do.

Telling us about a problem

If you believe you have found a security problem affecting us or anything we have built, please email [email protected] with enough detail to reproduce it. We will confirm we have received it, and we will not take action against anyone who reports something in good faith.

Let’s talk

Ready to put your
operations on autopilot?

Contact us