Security
How the service is built and operated, what access we have to your systems, and how to report a vulnerability.
Last updated August 6, 2026
Access to your systems
Every integration is read-only. Search Console and Google sign-in use OAuth scopes limited to reading performance data; payment providers use restricted read keys; analytics uses a project read key.
We cannot publish to your site, change your prices, refund a payment, or send email from your domain. The only write capability anywhere in the product writes to Woop, not to you.
Revoking access is immediate, from your provider or from your profile integrations, and stops collection at once.
Data protection
- All communications use HTTPS/TLS 1.2+ encryption; data is encrypted at rest with AES-256.
- Row-level security enforces per-user and per-project data boundaries at the query layer.
- Service credentials are stored as server-side secrets and never exposed to the browser.
- Inputs and generated content are validated and sanitized to reduce abuse risk.
- Daily encrypted backups with a 30-day window; restores tested quarterly.
Infrastructure
- Managed cloud infrastructure with regional data residency options.
- Infrastructure as code with peer-reviewed changes; no manual production access without a logged procedure.
- Sensitive endpoints require authentication, with CDN/WAF filtering at the network edge.
- Dependency and container scanning on every build.
Our people and process
SSO with mandatory MFA, least-privilege by default and quarterly access reviews. Confidentiality obligations in every contract, and security onboarding for everyone including founders.
Annual third-party penetration test; the current summary is available under NDA from security@woop1.com.
Compliance status
| Item | Status |
|---|---|
| SOC 2 Type II | Audit window opens Q4 2026 |
| GDPR / UK GDPR | DPA available, SCCs in place, EU residency option |
| India DPDP Act | Compliant; grievance officer named in the Privacy Policy |
| Penetration test | Last completed May 2026, no critical findings |
| Uptime target | 99.9% monthly for app and API |
We state where we actually are rather than claiming certifications we do not hold yet.
Reporting a vulnerability
Email security@woop1.com with steps to reproduce, or use the form below. We acknowledge within 24 hours, give an assessment within 72 hours, and aim to remediate critical issues within 7 days. Please do not publicly disclose issues until we have investigated and addressed them.