Security overview · Startup preview
Practical controls for a small, security-conscious startup.
This overview explains the practical controls used today without claiming an audit, certification, or perfect security.
Section 01
Current technical controls.
Loometry keeps its most important boundaries narrow and explicit.
- The public website is separate from customer and administrative services.
- The contact form can submit one strictly validated request but cannot read the contact database.
- Provider credentials, if accepted for agreed assessment work, stay server-side and are excluded from public forms and customer reports.
- Encrypted connections, strict input limits, access records, and security-focused logging.
- Customer reports omit credentials, customer records, and unnecessary internal identifiers.
- Cookie-free public pages that do not expose customer information or provider secrets.
Section 02
Startup security operations.
Controls are proportionate to the preview and will mature with customers and risk.
- Least-privilege service boundaries, server-only secret storage, dependency checks, route and contract gates, reviewed releases, and rollback checks for the public site.
- Assessment-specific operational, storage, retention, backup, deletion, and incident expectations must be stated in the applicable proposal or agreement rather than inferred from this overview.
- Loometry has not completed SOC 2, ISO 27001, penetration-test, or similar certification and does not imply otherwise.
Section 03
Customer responsibilities.
Security is shared, especially when customers bring provider accounts and evaluation data.
- Protect any provider account or credential approved for an assessment and remove access promptly when it is no longer needed.
- Use non-sensitive or appropriately approved evaluation data and review provider data-use settings.
- Validate reports and limitations before relying on results, and report unexpected access or activity promptly.
Section 04
Report a vulnerability or incident.
Email [email protected] with the subject “Security report”.
Include a concise description, affected URL or component, reproduction steps, and potential impact. Do not access other customers’ data, disrupt service, publish a live issue, or include working credentials in email.
Good-faith reports are welcome and will be prioritised according to credible impact and available startup resources. No bounty or fixed response time is promised.
Legal and trust centre
Find the related publication.
Questions and review requests may be sent to [email protected].
2026-08-28-preview