Skip to content New SourceLoop MCP: chat with your attribution data in Claude, ChatGPT & Cursor
SourceLoop

Security

Security built for revenue data

SourceLoop holds the data connecting your marketing spend to your customers: who visited, who converted, and what they were worth. This page sets out how that is protected, and links the documents your security team will ask for.

Last updated: August 18, 2026

Compliance

The frameworks we operate under

Where a mechanism is in place we say so and link the document. Where an audit is still running we say that instead, because an attestation you cannot read is not evidence.

How we protect it

Controls we are contractually bound to

Every measure below is written into Annex 2 of our Data Processing Addendum, so it is an obligation we owe you rather than a claim on a marketing page.

Your data, your control

You stay the controller. We stay the processor.

For the data captured by the SourceLoop snippet on your website, you decide what is collected and why. We process it on your documented instructions and nothing else. We do not sell personal information, we do not use your data to train models, and we do not use it to advertise our own or anyone else's products.

  • Export your data at any time, in full
  • Delete on request, during the term or after it
  • First-party only, with no third-party cookies set on your visitors
  • Configurable retention rather than indefinite storage

Responsible disclosure

Found something? We want to hear about it.

We work with the security research community and welcome reports of potential vulnerabilities. Report in good faith, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosing it. We will not pursue legal action against researchers who follow that.

  1. 1We acknowledge your report within two business days.
  2. 2We triage and confirm severity, and tell you what we found.
  3. 3We fix it, and keep you updated on progress.
  4. 4We credit you publicly if you would like us to.

FAQ

The questions security teams ask

How is my data encrypted?

In transit with TLS 1.2 or higher between your properties, our application, and our storage. At rest with AES-256 or stronger, including backups. These are contractual commitments in Annex 2 of our Data Processing Addendum, not marketing statements.

Where is my data hosted?

Customer data is stored in the United States, in established cloud data centres operated by our infrastructure sub-processors. A small number of ancillary sub-processors, such as our transactional email provider, operate in the European Union; each vendor's processing location is listed on our sub-processors page. Transfers are covered by the Standard Contractual Clauses and, for UK customers, the International Data Transfer Addendum, both incorporated into our DPA. If you have a specific residency requirement, contact us before you sign so we can confirm what is possible.

Do you have a Data Processing Addendum I can sign?

Our DPA is pre-signed and published, so there is usually nothing to negotiate. It incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, names our sub-processors, and sets out our technical and organizational measures in Annex 2.

How quickly are security incidents reported?

We notify affected customers without undue delay and within 72 hours of confirming a personal data breach, with the nature of the breach, the categories and approximate volume of data affected, likely consequences, and the steps taken. That commitment is in Section 9 of the DPA.

How are sub-processors managed?

Each one is vetted before engagement and contractually bound to protections no less strict than our own DPA, and we stay liable for their actions. We publish the current list, give at least 30 days notice before adding a new sub-processor, and you have the right to object on reasonable data-protection grounds.

What happens to my data when I leave?

At your choice we delete or return your data after the agreement ends, and delete remaining copies except where law requires retention. You can also request deletion at any time during the term through our data deletion process.

Do you respond to security questionnaires?

Yes. Most questions are answered by this page, the DPA, and the sub-processors list, which is usually faster for both of us. If your team needs a specific questionnaire completed or has questions under NDA, email [email protected].

Track every conversion to its true source

Capture and send full attribution data from every signup, lead, booking, and sale to your CRM and ad platforms, so you know exactly what's driving revenue.

Without SourceLoop

Untagged

Kayden Floyd

kayden@abc.com

  • SourceUnknown
  • MediumUnknown
  • CampaignUnknown
  • Landing pageUnknown
Journey
No touchpoints captured

With SourceLoop

Auto-tagged

Kayden Floyd

kayden@abc.com · Acme Co.

  • Channel Paid Social
  • CampaignFree_demo
  • Landing page/pricing
Journey
Synced to HubSpot Google Ads Meta