Skip to main content
Skip to main content

Loom Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Loom before Loom sends a questionnaire or a security document.

Loom's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Loom — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Loom's own trust page.

Loom was not found in the FedRAMP Marketplace. Checked August 2026.

This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
27 of 27 sources returned data
Questionnaire
93 / 133 answered
70% from public evidence
Last assessed
Aug 27, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 28.7 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Loom is not listed on the FedRAMP Marketplace (checked August 2026).
SOC 2 Status
Loom — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Loom returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Loom a Moderate Risk tier across 27 intelligence sources, 27 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 27 returning usable evidence. The Loom assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Loom Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

93 questions answered before Loom responds.

ThirdProof used public evidence to pre-fill 70% of a 133-question vendor security questionnaire — without waiting for Loom. The remaining 40 are listed as open, so the follow-up you send is short and specific.

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

GDPR compliance / DPA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

Loom explicitly does not sign Business Associate Agreements (BAAs) and is not HIPAA compliant as of February 2026, with official guidance stating that Loom cannot support customers' HIPAA obligations.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Encryption at rest claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q38

Do you have ISO 27001 certification?

ISO 27001 claim found on trust page (Vendor attested)

Public evidencemedium confidence

+ 88 additional evidence-backed answers

Get the Complete Loom Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Loom sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Clean domain reputation
  • Clean Safe Browsing Status
  • Clean Website Security Scan

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Data Security — 6 of 14 questions need vendor input
  • Incident Response — 5 of 10 questions need vendor input
  • Vulnerability Management — 5 of 8 questions need vendor input
  • Access Control — 4 of 12 questions need vendor input

Reviewing Loom for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Loom

Loom is a SaaS-based video recording and collaboration platform with moderate overall risk (Tier 3). The vendor demonstrates several strengths: a well-established domain (28+ years), minimal infrastructure exposure (2 open ports, both standard), clean domain reputation across threat intelligence engines, and a published commitment to 99.9% uptime availability.

Area Requiring Attention

The vendor's security program includes documented policies for secure development, change management, business continuity planning, and annual policy reviews. However, several gaps warrant attention.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this report was independently sourced through external data sources without vendor participation or input.

Investigation Findings

4 findings identified for Loom

1 medium3 low
medium

AI model training requires customer opt-out

Loom's [AI data usage policy](https://www.atlassian.com/legal/privacy-policy) indicates that customer data may be used for AI model training by default, with opt-out available upon request. This opt-out-by-default posture means customer data (including video content, transcripts, and metadata) could be processed by third-party AI systems unless the customer explicitly contracts out. …

low

Subprocessor list could not be parsed

Loom publishes a subprocessor page at https://loom.com/privacy/subprocessors, but automated parsing could not extract individual subprocessor entries. The page may use a non-standard format or dynamic rendering. …

low

5 certifications claimed but not independently verified

Loom's [published trust page](https://loom.com/security) mentions SOC 2, ISO 27001, FedRAMP, NIST, and GDPR. However, independent registry verification (FedRAMP Marketplace, IAF CertSearch for ISO 27001) returned no matches. …

low

Moderate security header configuration

HTTP security scanner scanning returned a grade of C (50/100) for HTTP security headers on loom.com. The vendor is missing Content-Security-Policy and X-Frame-Options headers, although HSTS is enabled. …

Security Strengths

Evidence that positively supports Loom's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Clean IP Reputation

IP Reputation

Established Domain (28+ years)

Domain Registration

Loom complete vendor assessment

Tier 3
Moderate Risk
93 / 133
questionnaire answers
27
sources checked
Aug 27, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 27, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Frequently asked about Loom

Is Loom FedRAMP authorized?+
Loom was not found in the FedRAMP Marketplace when it was checked on August 27, 2026. Absence of a public record is not evidence that the certification is absent; organisations with a hard requirement should confirm directly with the vendor.
Does Loom have SOC 2 Type II?+
Loom states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Loom on the OFAC sanctions list?+
Loom returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Loom's vendor risk tier?+
ThirdProof assigned Loom a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Loom.
Has Loom had any data breaches or security incidents?+
ThirdProof's adverse media and incident screening as of August 2026 did not surface a validated security incident involving Loom. Public sources do not record every incident, so this is not a guarantee that none occurred — ask Loom directly for its incident disclosure history and breach notification commitments.
Does Loom support HIPAA and sign BAAs?+
Loom explicitly does not sign Business Associate Agreements (BAAs) and is not HIPAA compliant as of February 2026, with official guidance stating that Loom cannot support customers' HIPAA obligations. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Loom security questionnaire?+
Yes. ThirdProof answered 93 of 133 questions (70%) about Loom from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 40 are listed as open, so the follow-up you send Loom is short and specific.
What evidence should I request from Loom?+
Public evidence settles a large part of the review, so the request you send should be short. Ask Loom for the current SOC 2 report and, where applicable, a bridge letter covering the period since the report date; the audit scope — which systems and services the report actually covers; written answers on data security, incident response, vulnerability management; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking Loom to re-confirm what is already documented.

If Loom is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Loom assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required