Legal
Security
nineloops holds a company's clients, money, people and conversations, so its security rules live where the data does. This page sets out how your workspace is protected and what you control.
Encryption
Data is encrypted in transit with TLS and encrypted at rest on our infrastructure. Tokens for the accounts you connect, such as a mailbox or a WhatsApp number, are encrypted at rest with a key held in the backend secrets. Records in the Docs vault are encrypted in your browser before they are stored, with a key derived from your workspace's identifier; that keeps them out of ordinary reads and exports, and it is not a secret we cannot reach. A vault key that nineloops itself cannot use is being built and is not in place yet. The desktop app talks to the same backend as the web.
Workspaces kept apart
Every record belongs to a workspace, and row level security in the database stops one workspace from reading or changing another's records. The rule runs on the server for every read and every write, however the data is reached.
Access control
- Eight roles, from owner to guest, and in the apps that give each record an owner (the CRM, Social, Studio, Distribute and Monitoring) a choice of whether people see every record, their team's or only their own.
- Permissions are enforced by the database, so the app, the API and the AI all get the same answer.
- Administrators can require two-step verification for every member and limit invitations to the company's own email domains.
- Sensitive HR fields can only be read through an audited call, and pay is visible only to the roles allowed to see it.
- In Finance, the person who raises a bill cannot approve it, and the approver cannot release the payment.
- Least-privilege access for our own systems and staff.
AI
- Levi runs on the sign-in of the person using it, so it can only read and change what that person can.
- Your workspace decides what Levi may do on its own, what it must ask first and what it may never do.
- Every action it takes is logged with how the records looked before, and most can be undone.
- AI employees in Brain work inside the permissions you give them, and anything customer-facing waits for a person to approve it.
Audit and your data
- An audit log of members and settings, and a history on records.
- Retention rules and legal holds on documents, enforced by the database.
- An export of every record in your workspace, one CSV per record type, from Settings whenever you want it. Uploaded files are listed in it by link and are downloaded from the module they live in.
Infrastructure
We run on established cloud providers, with continuous monitoring and regular backups. You remain responsible for keeping your own copies of important data.
No guarantee of absolute security
No product, system or method of transmission or storage can be guaranteed to be completely secure. While we work hard to protect your data, we cannot and do not warrant that the service will be free from unauthorised access, vulnerabilities or loss. You use the service at your own risk, and our responsibilities and liability are limited as set out in our Terms of Service.
Incident response
If we become aware of a security incident affecting your data, we will investigate and, where and to the extent required by applicable law, notify affected customers and authorities within the timeframes the law requires. See our Privacy Policy for details.
Responsible disclosure
If you find a vulnerability, email hello@publshr.ae. We will respond promptly, and we ask for a reasonable opportunity to fix it before any public disclosure.