Skip to main content
Trust Center

Your business’s data, treated like it’s yours

An AI agent repeating your business information has to be right, and the platform serving it has to be safe. This page is our security and privacy posture in plain language. Everything below is real, current, and checkable.

How we protect you

Your data stays yours, and only yours

Every business’s data is isolated at two independent layers. In the database itself and in every query the application makes. So a failure in one layer is caught by the other. No business can see another’s data, and analytics are visible only to the business they belong to.

Agents read, they don’t touch

Every agent-facing channel reads by design, with two deliberate exceptions: sending you an inquiry, which is rate-limited, size-capped, and stripped to plain text; and, on a form you approved, filling in the details a visitor already gave the assistant — only after the visitor confirms on the page, and CoreLoop never sends the form. No agent can edit your profile, change your settings, or reach your account. And responses never contain your personal details or your customers’ data.

You hold the switches

Every channel has its own on/off switch, and unpublishing takes everything offline — immediately for agent connections, within five minutes for tools already running in a visitor's browser. Verification badges are earned by proof, not purchased. Nothing about your business is served without your published say-so.

Abuse is priced out

Every public endpoint is rate-limited, responses are size-bounded, and every agent interaction is logged. No silent requests. Inquiry spam protection is shared across every door in, so limits can’t be stacked.

Privacy by construction

IP addresses are never stored in full anywhere in our audit trail; they’re truncated or hashed first. Agent identifiers are hashed before storage. Analytics identify patterns, never people.

Deletion means deletion

When you ask for your data to be deleted, a full cascade removes it across every system we operate. Database, analytics, caches, file storage. After a 7-day window in which support can still undo it. Our audit log is anonymised rather than deleted, so the record of what happened survives with the who removed, as GDPR intends.

Status, documents, contact

We hold no security certification, and we don’t display badges we haven’t earned or documents that don’t exist.

Put your business where AI can find it

Free to start. Live in minutes.