Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: Vendor attested — trust page
ThirdProof independently checks public intelligence sources to show what your team can verify about Loom before Loom sends a questionnaire or a security document.
Loom's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Loom — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Loom's own trust page.
⚠ Loom was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 27 returning usable evidence. The Loom assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Loom Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 70% of a 133-question vendor security questionnaire — without waiting for Loom. The remaining 40 are listed as open, so the follow-up you send is short and specific.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
Loom explicitly does not sign Business Associate Agreements (BAAs) and is not HIPAA compliant as of February 2026, with official guidance stating that Loom cannot support customers' HIPAA obligations.
Q23
Encryption at rest claim found on trust page (Vendor attested)
Q38
ISO 27001 claim found on trust page (Vendor attested)
+ 88 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Loom for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Loom
Loom is a SaaS-based video recording and collaboration platform with moderate overall risk (Tier 3). The vendor demonstrates several strengths: a well-established domain (28+ years), minimal infrastructure exposure (2 open ports, both standard), clean domain reputation across threat intelligence engines, and a published commitment to 99.9% uptime availability.
The vendor's security program includes documented policies for secure development, change management, business continuity planning, and annual policy reviews. However, several gaps warrant attention.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this report was independently sourced through external data sources without vendor participation or input.
4 findings identified for Loom
Loom's [AI data usage policy](https://www.atlassian.com/legal/privacy-policy) indicates that customer data may be used for AI model training by default, with opt-out available upon request. This opt-out-by-default posture means customer data (including video content, transcripts, and metadata) could be processed by third-party AI systems unless the customer explicitly contracts out. …
Loom publishes a subprocessor page at https://loom.com/privacy/subprocessors, but automated parsing could not extract individual subprocessor entries. The page may use a non-standard format or dynamic rendering. …
Loom's [published trust page](https://loom.com/security) mentions SOC 2, ISO 27001, FedRAMP, NIST, and GDPR. However, independent registry verification (FedRAMP Marketplace, IAF CertSearch for ISO 27001) returned no matches. …
HTTP security scanner scanning returned a grade of C (50/100) for HTTP security headers on loom.com. The vendor is missing Content-Security-Policy and X-Frame-Options headers, although HSTS is enabled. …
Evidence that positively supports Loom's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Established Domain (28+ years)
Domain Registration →Loom complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Loom? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Loom assessment above is already written; ask for it and it lands in your inbox.