Snapshot 58940
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Monitored and Powered by Trust Center gumloop.com security@gumloop.com Compliance overview Current compliance status across frameworks SOC 2 Type 2 Compliant GDPR Compliant HIPAA Compliant Featured documents Key security and compliance documentation Gumloop - SOC 2 Type II Audit Report (October 2025 to April 2026) Request access Q4 2025 Gumloop Pentest Request access Gumloop-CAIQv4.1.0-2026-05-14 Request access View all documents Compliance Program An overview of security controls in place Access Control and Authorization Access management policy established MFA required for critical services Password management policy enforced Password management policy established Data Management and Protection Consent for collecting and managing data obtained Data encrypted at rest Data encrypted in-transit Data management and retention policy established Data transfer mechanisms established External privacy inquiries managed Privacy disclosure and notification mechanisms established Privacy policy created and maintained Disaster Recovery Automated backups enabled Business continuity and disaster recovery policy established Data recovery process established Recovery data isolated Email Security DMARC policy and verification used Email account access restricted Email settings block malicious content Endpoint Security Automatic session locking enforced Unauthorized software on end-user devices addressed and removed Infrastructure Security Active discovery tools used Anti-malware deployed on infrastructure Automated security scanning performed on infrastructure Buckets not exposed publicly Configuration management system established Firewall restricts public access to infrastructure Infrastructure deployed using an infrastructure-as-code tool Network infrastructure continuously updated Production deployment access restricted Unauthorized assets addressed and removed Unique production database authentication enforced VPN used Web Application Firewall (WAF) used Monitoring and Incident Response Adequate audit log storage maintained Audit log management process maintained Audit logs collected Breach notification process established Incident response policy established Infrastructure performance monitored Log management used Network infrastructure monitored Organizational Security Acceptable use policy established Asset inventory maintained Asset management policy established Code of conduct acknowledged by employees Code of conduct established Company security commitments externally communicated External support resources available (i.e., documentation) Internal security audit performed Physical access restricted Physical security policy established Sanction policy established Security official assigned Service description communicated Software development lifecycle established Vendor agreements established Workstation use and security policy established Risk Management Risk management policy established Vendor inventory maintained Vendor management program established Vulnerability Management Penetration testing findings remediated Penetration testing performed within the last 12 months Vulnerabilities scanned Vulnerability management policy established