Security
Last updated: August 6, 2026
You are trusting us with your revenue data. Here is exactly how it is protected — stated plainly, no badges we have not earned.
Access to your systems
Loupe holds no credentials to your systems. Today your data arrives one way: you export records from the platforms you already use and upload the files here. There is no OAuth grant, no API key on file, no connection that could read more than you chose to export — and nothing that could write to your systems at all. That is the strongest access posture there is: we cannot touch anything you did not hand us.
If we ship live connections later, this section gets longer, not vaguer. Whether a genuinely read-only credential even exists depends on the platform — Intuit publishes a single QuickBooks accounting scope that carries both read and write, and CallRail issues a full-access account API key with no read-only type — and we will state each platform's real grant plainly rather than describe full access as “read-only” because it sounds better.
Encryption
All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest (AES-256). We hold no OAuth tokens or platform API keys for your systems — there are none to protect. The credentials our own infrastructure needs are stored in Cloudflare's Worker secret store, separate from the database — never in plaintext, never in application code or logs.
Tenant isolation
Every row of client data carries your workspace ID, and every query the application makes is scoped to it. We run on Cloudflare D1, which offers no database-level row policies, so this isolation lives in our code and is verified by test rather than assumed — we would rather tell you where the guarantee actually sits than name a database feature we do not use. Before we onboard a second client, we verify it by running the full query surface against two workspaces and confirming zero rows cross over. Nothing crosses workspaces in the other direction either: we do not pool client data to build benchmarks or peer comparisons.
AI boundaries
No AI model sees your data. Your numbers are computed by deterministic software from your own records — run it twice on the same records and you get the same answer, which is what makes the calculation something we can show you. The explanations around each figure are written templates filled with those computed numbers, not model output, and nothing about your business is sent to a model provider. If that ever changes, this page and the Privacy Policy will name the provider before it happens, not after.
Backups & continuity
Automated daily backups with 7-day retention, and we verify a restore before onboarding our first client. Your uploads originate in your platform of record and can always be re-exported and re-uploaded, so your history is never solely in our hands.
People & process
Access to production is limited to named engineers with hardware-key two-factor authentication; all access is logged. Credentials rotate on a schedule and immediately on any personnel change. We notify affected clients of any confirmed data incident within 72 hours.
Compliance roadmap
We align our controls with SOC 2 criteria and GDPR/CCPA requirements today. A formal SOC 2 Type II audit is on our roadmap — we will publish the report when it is complete, and will not claim the badge before then.
Report a concern
Security issue or question: hello@loupenow.com. We acknowledge within 1 business day.