loupe.Client sign in →

Security

Last updated: July 19, 2026 · Demo document — final versions reviewed by counsel before launch

You are trusting us with your revenue data. Here is exactly how it is protected — stated plainly, no badges we have not earned.

Access to your systems

Connections use each platform's official API with read-only scopes wherever the platform offers them. We cannot edit your jobs, invoices, campaigns, or books. You can revoke any connection at any time from the source platform or by asking us; revocation takes effect at the next sync.

Encryption

All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest (AES-256). OAuth tokens and API credentials are stored in a dedicated secrets vault, encrypted with keys held separately from the database — never in plaintext, never in application code or logs.

Tenant isolation

Every row of client data carries your workspace ID, and row-level security is enforced by the database itself — not just application code. Before we onboard a second client, we verify isolation by querying as one tenant and confirming zero rows from any other, tested through an authenticated client session (not the admin console, which bypasses these rules). Benchmarks only ever use aggregated, anonymized cohorts of 10+ businesses.

AI boundaries

AI models never compute your numbers — software does, from your records. Models only write explanations of pre-computed figures, every dollar amount is validated against the source computation before display, and our AI providers are contractually barred from training on your data.

Backups & continuity

Automated daily backups with 7-day retention, and we verify a restore before onboarding our first client. Source-system data can be re-synced from the platform of record, so your history is never solely in our hands.

People & process

Access to production is limited to named engineers with hardware-key two-factor authentication; all access is logged. Credentials rotate on a schedule and immediately on any personnel change. We notify affected clients of any confirmed data incident within 72 hours.

Compliance roadmap

We align our controls with SOC 2 criteria and GDPR/CCPA requirements today. A formal SOC 2 Type II audit is on our roadmap — we will publish the report when it is complete, and will not claim the badge before then.

Report a concern

Security issue or question: security@grovistra.com. We acknowledge within 1 business day.

© 2026 Grovistra · Loupe
PrivacyTermsSecurityFree leak check