Third Party Index

Snapshot 58940

Document
Trust center
URL
https://trust.gumloop.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
91081 bytes
SHA-256 (raw)
73b8d47d80e73fded5236d8069f309801412e0983bc791005d90bc79c2835d53
SHA-256 (normalized text)
b6b12b47060e3018dc021e834949fb1b932894c7225cfd0476aa23ba29acfe30

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Monitored and Powered by
Trust Center
gumloop.com
security@gumloop.com
Compliance overview
Current compliance status across frameworks
SOC 2 Type 2
Compliant
GDPR
Compliant
HIPAA
Compliant
Featured documents
Key security and compliance documentation
Gumloop - SOC 2 Type II Audit Report (October 2025 to April 2026)
Request access
Q4 2025 Gumloop Pentest
Request access
Gumloop-CAIQv4.1.0-2026-05-14
Request access
View all documents
Compliance Program
An overview of security controls in place
Access Control and Authorization
Access management policy established
MFA required for critical services
Password management policy enforced
Password management policy established
Data Management and Protection
Consent for collecting and managing data obtained
Data encrypted at rest
Data encrypted in-transit
Data management and retention policy established
Data transfer mechanisms established
External privacy inquiries managed
Privacy disclosure and notification mechanisms established
Privacy policy created and maintained
Disaster Recovery
Automated backups enabled
Business continuity and disaster recovery policy established
Data recovery process established
Recovery data isolated
Email Security
DMARC policy and verification used
Email account access restricted
Email settings block malicious content
Endpoint Security
Automatic session locking enforced
Unauthorized software on end-user devices addressed and removed
Infrastructure Security
Active discovery tools used
Anti-malware deployed on infrastructure
Automated security scanning performed on infrastructure
Buckets not exposed publicly
Configuration management system established
Firewall restricts public access to infrastructure
Infrastructure deployed using an infrastructure-as-code tool
Network infrastructure continuously updated
Production deployment access restricted
Unauthorized assets addressed and removed
Unique production database authentication enforced
VPN used
Web Application Firewall (WAF) used
Monitoring and Incident Response
Adequate audit log storage maintained
Audit log management process maintained
Audit logs collected
Breach notification process established
Incident response policy established
Infrastructure performance monitored
Log management used
Network infrastructure monitored
Organizational Security
Acceptable use policy established
Asset inventory maintained
Asset management policy established
Code of conduct acknowledged by employees
Code of conduct established
Company security commitments externally communicated
External support resources available (i.e., documentation)
Internal security audit performed
Physical access restricted
Physical security policy established
Sanction policy established
Security official assigned
Service description communicated
Software development lifecycle established
Vendor agreements established
Workstation use and security policy established
Risk Management
Risk management policy established
Vendor inventory maintained
Vendor management program established
Vulnerability Management
Penetration testing findings remediated
Penetration testing performed within the last 12 months
Vulnerabilities scanned
Vulnerability management policy established