alertloop runs on your infrastructure and touches your production systems. Here's exactly how we keep that access safe — described in terms of what the product actually does, not badges.
All traffic between your agents, your browser, and our platform is encrypted in transit using TLS. Agent connections additionally use mutual TLS (mTLS), so both sides authenticate each other before any data moves. Data stored on the platform — your account details, configuration, metrics, logs, and telemetry — is encrypted at rest.
Every customer gets a dedicated MySQL database — not a shared table with a tenant_id column. Your data lives in its own store, isolated from every other customer at the database boundary. High-volume telemetry (traces, spans, real-user metrics) is stored in ClickHouse with the same per-tenant separation.
AI-assisted and automated remediation is governed by per-asset autonomy settings that you configure. You decide what may run automatically and what requires a human to approve. Every automated action is recorded in an audit trail showing what ran, where, and why.
Your data is yours. We process it to operate the service on your behalf. We don't sell it, and we don't use it to train models for other customers. See our Privacy Policy for details on collection, use, and retention.
We build to recognised security practices and are working toward formal third-party certification. We're not going to claim a certificate we don't yet hold — when we complete one, it will show up here with the details to back it up.
Found something? We want to hear about it. Email hello@alertloop.io with the details and steps to reproduce. We'll acknowledge your report, keep you updated, and we won't pursue researchers who act in good faith and give us reasonable time to fix issues before disclosing.