generated: '2026-08-30' method: searched source: https://closedloop.sh/pricing, https://closedloop.sh/docs/guides/vendor-listing, https://trust.closedloop.sh note: >- probe-security-programs.py returned trust=none because trust.closedloop.sh renders entirely client-side and served no readable certification text to an anonymous fetch. It IS a real trust surface -- this file records what the provider publishes in machine-readable-adjacent form elsewhere on its own site, with each claim's source and status. trust_center: url: https://trust.closedloop.sh status: 200 readable: false readable_detail: >- Returns a Next.js SPA titled "Trust Vault" with no server-rendered content. No certification names, no document list and no report-request flow were readable without executing JavaScript. Recorded honestly: the page exists and 200s, but a machine cannot read it. linked_from_site: not-found linked_from_site_detail: >- No link to trust.closedloop.sh was found from the marketing navigation, the docs, or the vendor-listing guide. The subdomain was discovered by probe, not by following a first-party link. certifications: - name: SOC 2 Type II claimed: true source: https://closedloop.sh/pricing source_status: 200 evidence: >- Listed as "Included" on Free, Pay as you go and Enterprise in the published plan-comparison table, and again in the "On every plan" summary block. report_public: false report_note: The attestation report itself is not published; no request flow was readable. - name: ISO 27001 claimed: false - name: PCI DSS claimed: false note: Not applicable -- ClosedLoop AI processes no cardholder data. - name: HIPAA claimed: false - name: FedRAMP claimed: false privacy_program: vendor_listing_page: https://closedloop.sh/docs/guides/vendor-listing vendor_listing_status: 200 vendor_listing_note: >- A genuinely unusual artifact: a documentation page written FOR the buyer's security, privacy or procurement team, giving the legal entity, registered address, processor role, contacts, data categories and every policy link in a copy-paste block. Most providers make a buyer assemble this from a PDF. legal_entity: ClosedLoop Labs LLC, doing business as ClosedLoop AI registered_address: 7901 4th St N Ste 300, St. Petersburg, FL 33702, United States role: Data processor / vendor privacy_contact: dpo@closedloop.sh support_contact: support@closedloop.sh documents: - name: Privacy Policy url: https://closedloop.sh/privacy status: 200 - name: Data Processing Agreement url: https://closedloop.sh/dpa status: 200 - name: Subprocessors url: https://closedloop.sh/subprocessors status: 200 - name: AI Terms url: https://closedloop.sh/ai-terms status: 200 - name: Terms of Service url: https://closedloop.sh/terms status: 200 data_residency: regions: [us, eu] selection: chosen during onboarding, per workspace guarantee: >- "During normal operations, EU workspace data does not leave the EU region." Carried through every surface -- app (eu.app), REST API (eu.api), MCP (eu.mcp), SCIM and SSO all have EU equivalents. source: https://closedloop.sh/docs/guides/vendor-listing access_posture: read_only_connections: true read_only_source: https://closedloop.sh/pricing read_only_detail: >- "Read-only connections" is listed as an on-every-plan property, and the /v1 API is GET-only, which corroborates it from the contract side rather than from marketing alone. enterprise_controls: sso: [Okta OIDC, Google Workspace SAML, Microsoft Entra ID SAML] provisioning: SCIM 2.0 (Okta, Entra ID) with Group Push and role entitlements offboarding: Global Token Revocation endpoint (Okta Universal Logout) plan_gate: Enterprise cross_ref: conformance/closedloop-conformance.yml vulnerability_disclosure: published: false probes: - url: https://closedloop.sh/.well-known/security.txt status: 404 - url: https://api.closedloop.sh/.well-known/security.txt status: 404 - url: https://docs.closedloop.sh/.well-known/security.txt status: 404 - url: https://closedloop.sh/security.txt status: 404 - url: https://closedloop.sh/security status: 404 detail: >- No security.txt on any host, no /security page, no bug-bounty program found on HackerOne, Bugcrowd or Intigriti, and no disclosure policy in the docs. A researcher who finds a vulnerability has no published channel other than support@closedloop.sh. This is the clearest single gap in an otherwise strong security posture, and it is cheap for the provider to close.