Your business’s data, treated like it’s yours
An AI agent repeating your business information has to be right, and the platform serving it has to be safe. This page is our security and privacy posture in plain language. Everything below is real, current, and checkable.
How we protect you
Your data stays yours, and only yours
Every business’s data is isolated at two independent layers. In the database itself and in every query the application makes. So a failure in one layer is caught by the other. No business can see another’s data, and analytics are visible only to the business they belong to.
Agents read, they don’t touch
Every agent-facing channel reads by design, with two deliberate exceptions: sending you an inquiry, which is rate-limited, size-capped, and stripped to plain text; and, on a form you approved, filling in the details a visitor already gave the assistant — only after the visitor confirms on the page, and CoreLoop never sends the form. No agent can edit your profile, change your settings, or reach your account. And responses never contain your personal details or your customers’ data.
You hold the switches
Every channel has its own on/off switch, and unpublishing takes everything offline — immediately for agent connections, within five minutes for tools already running in a visitor's browser. Verification badges are earned by proof, not purchased. Nothing about your business is served without your published say-so.
Abuse is priced out
Every public endpoint is rate-limited, responses are size-bounded, and every agent interaction is logged. No silent requests. Inquiry spam protection is shared across every door in, so limits can’t be stacked.
Privacy by construction
IP addresses are never stored in full anywhere in our audit trail; they’re truncated or hashed first. Agent identifiers are hashed before storage. Analytics identify patterns, never people.
Deletion means deletion
When you ask for your data to be deleted, a full cascade removes it across every system we operate. Database, analytics, caches, file storage. After a 7-day window in which support can still undo it. Our audit log is anonymised rather than deleted, so the record of what happened survives with the who removed, as GDPR intends.
Status, documents, contact
We hold no security certification, and we don’t display badges we haven’t earned or documents that don’t exist.