Loom security review: SOC 2, AI training & subprocessors

What Loom publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
100/100
SOC 2
SOC 2
ISO 27001
Claimed
Trains AI on your data?
See quote
Subprocessors
38 listed

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Loom train AI on your data?

Mentions using data for AI, with an opt-out

Loom's own words (atlassian.com/legal/privacy-policy):

You can control whether you receive these communications as described below at “How to access and control your information” under "Opt-out of communications." To provide customer support: We use your information to resolve technical issues you encounter, to respond to your req…

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
You can control whether you receive these communications as described below at “How to access and control your information” under "Opt-out of communications." To provide customer support: We use your information to resolve technical issues you encounter, to respond to your req…
atlassian.com/legal/privacy-policy

Certifications Loom claims

Certification or reportMentioned on
SOC 2atlassian.com/legal/security-measures
ISO/IEC 27001atlassian.com/legal/security-measures
HIPAAatlassian.com/legal/data-processing-addendum
FedRAMPatlassian.com/legal/security-measures

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Loom for the SOC 2 report or ISO certificate.

Loom subprocessors

Loom lists 38 subprocessors on atlassian.com/legal/privacy-policy:

Security features mentioned

SSO / SAMLMentioned
SCIM provisioningMentioned
Multi-factor authenticationMentioned
Encryption at restMentioned
Encryption in transitNot found
Penetration testingMentioned
Bug bounty / disclosure programMentioned
Audit logsMentioned
Data residencyMentioned EU, United States, UK, United Kingdom
security.txt contacthttps://www.atlassian.com/trust/security/report-a-vulnerability

Key documents

Trust / security centerloom.com/security
Privacy policyatlassian.com/legal/privacy-policy
Subprocessor listatlassian.com/legal/privacy-policy
Data processing agreement (DPA)atlassian.com/legal/data-processing-addendum
AI policyNot found
TermsNot found
Status pageloom.status.atlassian.com

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15Yes
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from Loom's public pages. It is not a rating of how secure Loom is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Productivity vendors

Airtable · Asana · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · DocuSign · Dropbox · Evernote · Figma

Source: Loom's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with Loom. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.