Trust & security
Security Policy
Last updated:
How LoopIQ handles security for its hosted platform and integrations, and how to report a concern.
Scope
This policy describes security practices and responsibilities for the LoopIQ hosted platform and its integrations, operated by FusionOne Inc. Customer-managed enterprise deployments may have different infrastructure and controls, as defined in the applicable agreement.
This policy is a security overview, not an independent certification, a guarantee of uninterrupted service, or a service-level agreement. Contractual commitments are defined in the applicable customer agreement.
Data handling and external processing
LoopIQ processes and stores customer data outside Atlassian products to provide synchronization, work management, traceability, and release-evidence functionality. Depending on the products connected, permissions granted, and configuration, this may include work-item content, comments, relationships, project and release metadata, account identifiers, webhook payloads, and evidence records.
The hosted backend uses Google Cloud infrastructure. Integration audit records can include organization and actor references, actions, outcomes, and timestamps. Operational logging and hosting involve infrastructure providers; storing data outside Atlassian also means that Atlassian's data-residency settings do not automatically apply to LoopIQ.
AI-enabled features may process selected work content and context through the model service used for that feature. Customers should review their configuration and applicable processing terms before submitting sensitive information. Contact us for information about processing locations and service providers applicable to your deployment.
Encryption and credentials
LoopIQ's public hosted application and API endpoints use HTTPS to protect traffic in transit. Customer content stored in Google Cloud storage services is protected by Google's default encryption at rest. This statement describes that infrastructure protection; it does not assert that every customer device, exported file, or independently connected service uses full-disk encryption.
The Atlassian OAuth integration encrypts stored access and refresh tokens at the application layer. Credentials and tokens must not be included in support messages, screenshots, or vulnerability reports. Customers remain responsible for protecting downloaded exports and any credentials used in their own systems.
Reference: Google Cloud default encryption at rest.
Authentication and access controls
LoopIQ uses authenticated access, organization context, and role-based permissions to govern access to platform operations. Administrators should grant only the access each user or integration needs and review assignments when responsibilities change.
The Atlassian OAuth connector redirects users to Atlassian to authorize access. It does not require users to give LoopIQ their Atlassian account password or a personal access token. Access depends on the permissions granted and the connected site's configuration. Administrators can revoke the authorization through Atlassian.
Revoking authorization stops the connector from using that grant to access Atlassian; it does not by itself delete previously synchronized records, audit history, or backups held by LoopIQ. Contact us to request deletion or clarify retention requirements.
Report a vulnerability or security incident
Send security concerns to sales@loopiq.com with the subject “Security report — LoopIQ”. Include the affected service or URL, a description of the issue, the time observed and time zone, potential impact, and safe steps to reproduce it. Redact personal data and secrets. Ask for a suitable transfer method before sending sensitive evidence.
Report suspected unauthorized access promptly. If safe to do so, revoke affected integration grants or credentials and preserve relevant timestamps and diagnostic details. We assess reported concerns and coordinate follow-up through the reporting contact. This policy does not promise a fixed response or resolution time.
Responsible security testing
Request written authorization before testing production systems. Limit authorized testing to accounts and data you control. Do not access another customer's data, disrupt services, use social engineering, or test third-party systems without their permission. If you encounter data that is not yours, stop testing and report the issue without copying or disclosing it.
This reporting channel does not establish a paid bug bounty, authorize testing, or grant legal safe harbor. Do not publicly disclose sensitive findings before coordinating with us.
Customer responsibilities and assurance requests
Customers are responsible for authorizing integrations, choosing synchronization scope, maintaining appropriate user access, securing their endpoints, and reviewing actions and outputs before relying on them. Avoid submitting secrets or unnecessary sensitive data in work items, prompts, comments, and attachments.
LoopIQ release certifications and compliance reports organize evidence and approval decisions. They are not independent security certifications or legal advice and do not replace the customer's compliance obligations.
For security questionnaires, data-processing terms, retention requirements, or evidence of specific controls, contact us before making a procurement decision. Only rely on certifications, residency commitments, or service levels expressly documented for the service you are purchasing.
Related policies
Read our Privacy Policy and Terms of Service. We may update this security policy as our service and practices evolve; the date above identifies the latest revision.