What Loom publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.
"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.
Mentions using data for AI, with an opt-out
Loom's own words (atlassian.com/legal/privacy-policy):
You can control whether you receive these communications as described below at “How to access and control your information” under "Opt-out of communications." To provide customer support: We use your information to resolve technical issues you encounter, to respond to your req…
Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.
You can control whether you receive these communications as described below at “How to access and control your information” under "Opt-out of communications." To provide customer support: We use your information to resolve technical issues you encounter, to respond to your req…
atlassian.com/legal/privacy-policy
| Certification or report | Mentioned on |
|---|---|
| SOC 2 | atlassian.com/legal/security-measures |
| ISO/IEC 27001 | atlassian.com/legal/security-measures |
| HIPAA | atlassian.com/legal/data-processing-addendum |
| FedRAMP | atlassian.com/legal/security-measures |
Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.
A certification on a website is a claim. For anything sensitive, ask Loom for the SOC 2 report or ISO certificate.
Loom lists 38 subprocessors on atlassian.com/legal/privacy-policy:
| SSO / SAML | Mentioned |
| SCIM provisioning | Mentioned |
| Multi-factor authentication | Mentioned |
| Encryption at rest | Mentioned |
| Encryption in transit | Not found |
| Penetration testing | Mentioned |
| Bug bounty / disclosure program | Mentioned |
| Audit logs | Mentioned |
| Data residency | Mentioned EU, United States, UK, United Kingdom |
| security.txt contact | https://www.atlassian.com/trust/security/report-a-vulnerability |
| Trust / security center | loom.com/security |
| Privacy policy | atlassian.com/legal/privacy-policy |
| Subprocessor list | atlassian.com/legal/privacy-policy |
| Data processing agreement (DPA) | atlassian.com/legal/data-processing-addendum |
| AI policy | Not found |
| Terms | Not found |
| Status page | loom.status.atlassian.com |
| Check | Points | Result |
|---|---|---|
| Security or trust page | 15 | Yes |
| Certifications listed | 20 | Yes |
| Privacy policy | 10 | Yes |
| Subprocessor list | 15 | Yes |
| DPA available | 10 | Yes |
| AI training policy stated | 15 | Yes |
| security.txt contact | 5 | Yes |
| Status page | 10 | Yes |
The score measures how much of a standard security review our reader could answer from Loom's public pages. It is not a rating of how secure Loom is, and a "No" can mean the document exists where our reader couldn't see it.
Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.
Airtable · Asana · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · DocuSign · Dropbox · Evernote · Figma
Source: Loom's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with Loom. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.