On this page
The claim behind the badge
"Marketplace and carrier credentials are encrypted at rest using AES-256." AES-256 is a technical security control, not an external certification and not a guarantee that security incidents can never occur.
1.What is protected
When you connect a marketplace or carrier account to Loopmerce, you provide credentials such as API keys or connection details so the products can act on your behalf. These marketplace and carrier credentials are encrypted at rest using AES-256. The badge in our footer refers specifically to this control. It does not state that every piece of data in Loopmerce uses the same method.
2.What AES-256 means
AES-256 is the Advanced Encryption Standard using a 256-bit key. It is a widely used, standardised symmetric encryption algorithm for protecting stored data. When we say credentials are encrypted at rest using AES-256, we mean that the stored credential values are protected using this algorithm so that they are not held in plain readable form.
3.Credentials at rest
Connected marketplace and carrier credentials are stored in encrypted form using AES-256. This reduces the risk that stored credential values could be read directly from storage. We manage the encryption in line with good practice and do not publish the details of our key management, because doing so would itself be a security risk.
4.Data in transit
Data exchanged between your browser or device and Loopmerce, and between Loopmerce and the services it connects to, is protected in transit using Transport Layer Security (TLS). Encryption in transit protects information while it moves across networks.
5.Account isolation
Each company's data is logically isolated so that one customer's account and data are separated from another's. Isolation is a core part of how the products keep operational data and credentials associated with the correct account.
6.Access controls
Access to systems and data is controlled on a least-privilege basis, so that people and services have only the access they need. Authentication protects account sign-in, and access to sensitive functions is limited and logged.
7.Backups
We maintain backups to support recovery and service continuity, and we test restoration. Backups follow a normal rotation cycle, and data deleted from live systems is removed from backups as those backups are overwritten on their cycle.
8.Incident response
We maintain incident-response procedures to identify, investigate and respond to security events. Where a personal data breach affects data we process on a customer's behalf, we notify the affected customer without undue delay after becoming aware, as described in our Data Processing Agreement.
9.What encryption does not mean
Important limits on this claim
AES-256 is a technical security control, not an external certification and not a guarantee that security incidents can never occur.
To be clear about what we do not claim:
- We do not claim AES-256 certification;
- We do not claim end-to-end encryption;
- We do not claim zero-knowledge encryption;
- We do not claim "military-grade" certification;
- We do not claim breach-proof or perfect security;
- We do not claim that all customer data is encrypted with AES-256; the AES-256 claim is specific to marketplace and carrier credentials at rest;
- We do not claim that encryption keys can never be accessed.
No security measure eliminates all risk. We describe our controls accurately and without guarantees.
10.Responsible disclosure
If you believe you have found a security vulnerability in Loopmerce, we welcome a responsible report. Please email info@loopmerce.com and include:
- A clear description of the issue;
- Steps to reproduce it;
- The affected URL or feature;
- Any supporting evidence;
- How we can contact you.
When investigating, please do not:
- Access, modify or delete data that is not yours;
- Disrupt or degrade our services;
- Use social engineering against our users or staff;
- Publicly disclose the issue before we have had a reasonable opportunity to remediate it.
We appreciate responsible research. This page does not create a paid bug-bounty program.