Security

Security, stated plainly

What Sloose does to protect your data today, and what it does not do yet. Every line on this page describes the product as it runs now. Last checked 3 October 2026.

In short

HTTPS on every address

Plain HTTP is redirected to HTTPS and browsers are told to stay on HTTPS. Connections need TLS 1.2 or newer.

CRM credentials encrypted

The token that lets Sloose reach your CRM is encrypted at rest with AES-256-GCM. The key is kept outside the database.

Stored in one region, deleted on schedule

The database and your imported files are in Cloudflare’s Oceania region, and are deleted when your plan’s history window passes.

You decide what the AI sees

Allow, Masked or Never for the organisation, and Exclude from AI for any field. The AI runs only when somebody asks it to.

Two-factor sign-in

An authenticator app, backup codes or passkeys, for anyone. Our staff need one to use a support tool.

A record of who did what

Your settings keep a history of every change. Every action our staff take on your organisation is logged.

HTTPS on every sloose.com address

The website, the app, the API, the documentation and the page your CRM tab loads all answer over HTTPS only.

We checked each address on 3 October 2026. This is a setting on our domain at Cloudflare.

Where your data lives

How long we keep it

WhatHow long
Imported files, their corrections, and run historyYour plan’s history window, counted from when the import was last changed or run: 7 days on Free, 30 on Team, 365 on Business and Enterprise. Up to 30 days longer after a change of plan. Deleting an import deletes its files sooner.
Sessions, with the address and browser each was made fromUntil you sign out, or a month after the session expires.
Billing records7 years, as Australian tax law requires.

Closing your organisation. An owner can close it from the app by typing its name. Sloose asks Zoho to revoke every connection, cancels the subscription, and erases the organisation’s data within 30 days. Until then, a closure made by mistake can be undone through support.

Deleting your account. Anyone can delete their own account from Your account. Every session ends, every sign-in method is removed, and Sloose asks Zoho to revoke the CRM connections you made yourself. An organisation’s records then read “a deleted person” where your name and email address were. If you are the only owner of an organisation, close it or make someone else an owner first.

Section 6 of the privacy policy has the full schedule.

AI and your data

The AI runs only when somebody asks it to: a button in the app, such as Draft everything, Ask AI or Explain, or an AI assistant or API client you connected calling an AI tool. Running an import never calls the AI.

An administrator chooses what the AI may see, once for the organisation:

Exclude from AI is set per field. An excluded field’s values are never sent, in any form, under any setting. The field’s examples are sent in their place, so they should be made up. A column whose name matches an excluded field is withheld too. That match is by name, so a column under a name nothing recognises follows the organisation’s setting.

Your question, your column names, your field definitions and any formula being asked about are sent under every setting, since the AI has nothing to work from without them. Requests go through Cloudflare’s AI Gateway to Anthropic. The gateway keeps a log of each request and its answer, sample values included, until newer requests replace it. It holds the most recent 10 million.

How the AI handles your data in the docs says what each feature sends.

Accounts and access

Signing in

People sign in with Zoho, with an emailed link and the six-digit code that comes with it, or with a passkey. There are no passwords. Sign-in is rate-limited, and the emailed link is protected by Cloudflare Turnstile. A session lasts eight hours and extends while it is in use.

Two-factor sign-in

Roles and invitations

An organisation has four roles: Owner, Administrator, Builder and Operator. People join only by invitation, an invitation lasts seven days, and it must be accepted by the email address it was sent to. Administrators change roles on People. Nobody can raise their own role.

API tokens

Only an administrator who is signed in can create or revoke an API token. Another token cannot. A token is stored as a hash, and acts at the lower of its own role and its creator’s role today. A token can read, configure and run imports. It cannot manage people, connections or billing.

AI assistants

Assistants that support MCP, such as Claude, connect with OAuth. You approve the assistant on a Sloose page and choose which organisation it may use. Each person sees the apps they allowed under Your account, on Apps with access. Removing one stops every token it was given.

The Sloose consent page asking whether to let an AI assistant use an organisation.
An assistant connects by OAuth. You choose the organisation it may use, and you can remove it later.

When our staff help you

Only named Dinode staff can reach support tools. To help you, a staff member can view your organisation as one of its members. That view is read-only unless they record a reason and type your organisation’s name. It never creates an API token, an invitation or anything else that would outlast it, and it never changes your billing.

Logs

Every change our staff make, and every time they open your organisation, is recorded in a log that is only ever added to. Your organisation’s settings keep their own history in the app, one entry for each value changed, with who changed it and when. Role changes, removals and invitations are recorded on People.

Your CRM, and the code we run for you

What we don’t have yet

  • No SOC 2 report and no ISO 27001 certification.
  • No single sign-on (SAML or OIDC) and no SCIM.
  • No choice of data region.
  • No copy of our staff log for you to read, and no export of your change history.
  • No status page, no uptime agreement, no published penetration test and no bug bounty.

If one of these stops you, tell us. It helps us decide what to build next.

Report a vulnerability

Email security@sloose.com. Tell us the address, the steps to reproduce it and what you saw. Please do not read other people’s data or disrupt the service while you test. Oursecurity.txt says the same.

Documents

Sub-processors

Sub-processorWhat forWhere
Cloudflare, Inc.Hosting, database, file storage, network, AI Gateway, emailGlobal network; database and files in Oceania
Anthropic, PBCThe AI modelUnited States
Stripe, Inc.Payments and invoicingUnited States, with EU and Australian entities
Userback Pty LtdSupport requests and feedbackAustralia; hosted in the United States
GitHub, Inc.A copy of each support request, to track the workUnited States
Zoho CorporationYour CRM, its API and Zoho sign-inYour Zoho account’s data centre

The DPA is the binding list.

Questions people ask

Is Sloose SOC 2 compliant?
No. Sloose has no SOC 2 report and no ISO 27001 certification. We offer a data processing addendum, and the EU Standard Contractual Clauses and the UK Addendum on request. This page lists what we do today.
Does Sloose support SSO or SAML?
Not yet. People sign in with Zoho, with an emailed link and code, or with a passkey, and anyone can add a second factor. There is no password to leak.
Where is my data stored?
The database and the files you import are stored in Cloudflare’s Oceania region. Some services are elsewhere: the AI gateway’s log, our AI provider, our support tool and our issue tracker are in the United States. Where your data lives has the full list.
Does the AI see my customer data?
Only what your organisation’s setting allows, and only when somebody asks the AI for help. Under Allow it sees sample values as they are. Under Masked it sees their shape. Under Never it sees no values at all. A field marked Exclude from AI is never sent under any setting. See AI and your data.
Can Sloose delete records in my CRM?
Sloose never deletes a CRM record itself. It creates and updates records, and every write belongs to a run that is recorded. An update is sent as written, so for a subform or a multi-select lookup your CRM can treat it as removing entries.
How do I delete my data?
Delete an import to delete its files. An owner can close the organisation from the app, and its data is erased within 30 days. Anyone can delete their own account from Your account. The privacy policy has the schedule.

See what the AI is sent before you start

The docs list what each AI feature sends under each setting. Start on the free plan when you are ready. No card needed.

How the AI handles your dataStart free