Skip to content

    Security

    How the service is built and operated, what access we have to your systems, and how to report a vulnerability.

    Last updated August 6, 2026

    Access to your systems

    Every integration is read-only. Search Console and Google sign-in use OAuth scopes limited to reading performance data; payment providers use restricted read keys; analytics uses a project read key.

    We cannot publish to your site, change your prices, refund a payment, or send email from your domain. The only write capability anywhere in the product writes to Woop, not to you.

    Revoking access is immediate, from your provider or from your profile integrations, and stops collection at once.

    Data protection

    • All communications use HTTPS/TLS 1.2+ encryption; data is encrypted at rest with AES-256.
    • Row-level security enforces per-user and per-project data boundaries at the query layer.
    • Service credentials are stored as server-side secrets and never exposed to the browser.
    • Inputs and generated content are validated and sanitized to reduce abuse risk.
    • Daily encrypted backups with a 30-day window; restores tested quarterly.

    Infrastructure

    • Managed cloud infrastructure with regional data residency options.
    • Infrastructure as code with peer-reviewed changes; no manual production access without a logged procedure.
    • Sensitive endpoints require authentication, with CDN/WAF filtering at the network edge.
    • Dependency and container scanning on every build.

    Our people and process

    SSO with mandatory MFA, least-privilege by default and quarterly access reviews. Confidentiality obligations in every contract, and security onboarding for everyone including founders.

    Annual third-party penetration test; the current summary is available under NDA from security@woop1.com.

    Compliance status

    Compliance status
    ItemStatus
    SOC 2 Type IIAudit window opens Q4 2026
    GDPR / UK GDPRDPA available, SCCs in place, EU residency option
    India DPDP ActCompliant; grievance officer named in the Privacy Policy
    Penetration testLast completed May 2026, no critical findings
    Uptime target99.9% monthly for app and API

    We state where we actually are rather than claiming certifications we do not hold yet.

    Reporting a vulnerability

    Email security@woop1.com with steps to reproduce, or use the form below. We acknowledge within 24 hours, give an assessment within 72 hours, and aim to remediate critical issues within 7 days. Please do not publicly disclose issues until we have investigated and addressed them.