Cloop

Cloop Security Overview

Last updated: 2026-02-15 Intended audience: Prospective and current customers evaluating Cloop's security posture


Company

Cloop is built and operated by ROFFI Oy, a Finnish customer experience consultancy. We are a small, technical team of three. Security is not a department — it's how we build.


Infrastructure

Hosting

ComponentProviderLocation
Application serverHetzner Online GmbHHelsinki, Finland (EU)
DatabaseSelf-managed on Hetzner VPSHelsinki, Finland (EU)
Cache / state storeSelf-managed on Hetzner VPSHelsinki, Finland (EU)
Object storage (documents)Hetzner S3-compatibleHelsinki, Finland (EU)
TLS certificatesLet's EncryptAutomated renewal
DNSHetzner DNSEU

All data is stored and processed exclusively within the European Union.

Network

Operating System


Application Security

Authentication

Authorization

Input Validation

Rate Limiting

Multi-tier rate limiting applied across all API endpoints (chat, authentication, admin, public). Limits are enforced per IP using a sliding window algorithm.

Budget Controls


Data Security

Encryption

Multi-Tenant Isolation

Data Retention


AI Security

Data Flow

  1. Visitor message arrives at our server
  2. Vector similarity search runs locally (PostgreSQL + pgvector) — no external call
  3. Relevant content chunks + visitor message sent to Nebius AI API for response generation
  4. Response streamed back to visitor

What Goes to AI Provider

What Does NOT Go to AI Provider

AI Provider Commitment

Nebius AI Studio does not use API inputs/outputs for model training. Processing is transient.


Monitoring and Incident Response

Audit Logging

Deployment Verification

Incident Response

As a small team, our process is direct:

  1. Detection via monitoring, logs, or user report
  2. Immediate assessment by the engineering team
  3. Containment and fix
  4. Notification to affected customers (within 48 hours for data breaches per DPA)
  5. Post-incident review and prevention measures

Security issues: security@cloop.io


Compliance

FrameworkStatus
GDPRCompliant — Finnish company, EU data processing, DPA available, data subject rights supported
ePrivacy DirectiveWidget uses localStorage (not cookies) for visitor identification
SOC 2Not yet — planned as customer base grows
ISO 27001Not yet — planned as customer base grows

Security Assessments

We conduct regular internal security audits covering:

Our most recent audit (February 2026) found no critical issues, with all high-severity findings addressed or mitigated.


Responsible Disclosure

If you discover a security vulnerability in Cloop, please report it to security@cloop.io. We appreciate responsible disclosure and will:

We do not currently offer a bug bounty program.


Questions

For security-related questions or to request additional information for your security review:

Email: security@cloop.io General: legal@cloop.io