Signal Loom, Inc. is the identity control plane for the enterprise agent era — governing Non-Human Identities (NHIs) at the credential layer across cloud, agent, and directory infrastructure. Signal Loom, Inc., 2810 N Church St, PMB 526509, Wilmington, DE 19802, United States.
For privacy inquiries, contact us at: legal@signal-loom.ai
Signal Loom, Inc. is established in the United States and offers the Free Scan service to business users and organizations in the European Union. Because we are not established in the EU but offer the Service to individuals located in the EU within the meaning of Article 3(2) GDPR, we are required to designate a representative in the Union under Article 27 GDPR. We will appoint an EU Representative to act on our behalf as the point of contact for GDPR-related inquiries from EU data subjects and supervisory authorities.
EU Representative status: To be appointed. Signal Loom, Inc. commits to appoint an EU Representative within 60 days of the first publication of this Policy or before the first EU data subject onboarding (whichever is sooner). Once appointed, the EU Representative's name, address, and direct contact details will be added to this section.
Until an EU Representative is in place, EU data subjects may contact hello@signal-loom.ai directly for all GDPR-related inquiries, and Signal Loom, Inc. will respond per Section 9 (Your Rights).
This Privacy Policy applies to personal data and organizational data collected through the Signal Loom Free Scan, including the web interface at signal-loom.ai, any downloadable scan agents or connectors, and communications related to the Free Scan service.
This Policy does not apply to Signal Loom, Inc.'s paid enterprise products (which are governed by separate Data Processing Agreements) or to third-party websites linked from our properties.
When you register to use the Free Scan, we collect:
Name and email address
Company or organization name
Job title or role (optional, but helps us understand usage)
Account credentials (password stored as a salted cryptographic hash — never in plaintext)
To perform a scan, you may submit or connect:
API tokens, OAuth credentials, or read-only access keys scoped to the target environment
Cloud account identifiers (e.g., AWS Account ID, Azure Tenant ID, GCP Project ID)
Directory or identity provider configuration details
Agent framework configuration metadata (e.g., MCP server endpoints, A2A relay addresses)
We process this data solely to perform the scan and return results to you. We do not use access credentials for any purpose other than executing the authorized scan.
The Service generates an inventory of discovered Non-Human Identities in your environment, including associated metadata such as credential types, expiration dates, permission scopes, and risk indicators. This Output is your data.
We automatically collect certain technical data when you use the Service:
IP address and approximate geolocation (country/region)
Browser type, operating system, and device characteristics
Pages visited, features used, and interaction timestamps
Scan configuration parameters (not credential values)
Error logs and performance telemetry
This data is used to operate, maintain, secure, and improve the Service.
If you contact us by email or through our website, we retain the content of those communications and your contact information to respond to your inquiry and improve our support.
We use the information we collect to:
Provide the Service: Execute scans, generate reports, and deliver results to you.
Account Management: Create and manage your account, authenticate your identity, and process any necessary communications.
Security and Fraud Prevention: Detect, investigate, and prevent unauthorized access, abuse, or violations of our Terms of Service.
Service Improvement: Analyze usage patterns, diagnose technical issues, and develop new features — using aggregated and anonymized data only.
Compliance: Meet applicable legal obligations, including responding to lawful requests from authorities.
Communications: Send transactional messages (scan results, account notifications) and, with your consent, product updates. You may opt out of non-transactional communications at any time.
We do not use your Submitted Data or scan results to train machine learning models without your explicit consent.
We process your personal data on the following legal bases under Article 6(1) GDPR. Performance of a contract (Article 6(1)(b)): creating and managing your account, authenticating you, executing the scan you request, and delivering results and transactional messages. Consent (Article 6(1)(a)): sending product or marketing updates, and any use of Submitted Data or scan results to train machine-learning models; you may withdraw consent at any time without affecting the lawfulness of prior processing. Compliance with a legal obligation (Article 6(1)(c)): meeting tax, accounting, and lawful-request obligations. Legitimate interests (Article 6(1)(f)): the specific interests described below. Where a purpose could rest on more than one basis, we rely on the basis stated here for that purpose.
Where we rely on Article 6(1)(f) GDPR legitimate interests as our lawful basis for processing your personal data, the specific interests we rely on are:
1. Providing and improving the Free Scan service — operating the scan, generating reports, and evolving the product based on aggregate usage patterns and customer feedback.
2. Platform security and fraud prevention — rate-limiting, abuse detection, and maintaining audit logs for SOC 2 compliance and incident response.
3. Responding to user-initiated inquiries — answering questions submitted via hello@signal-loom.ai or via in-dashboard support requests.
4. Business operations — billing, accounting, and compliance reporting.
A Legitimate Interests Assessment (LIA) document outlining our balancing test for each of the above is available on request to hello@signal-loom.ai. You may object to processing based on legitimate interests at any time as described in Section 9 (Your Rights).
We do not sell, rent, or broker your personal data or your scan results. We may share data in the following limited circumstances:
We engage third-party vendors who process data on our behalf, subject to data processing agreements that restrict use to providing services to Signal Loom, Inc. Categories include: cloud infrastructure (hosting, storage), authentication providers, analytics platforms, and customer communication tools.
We may disclose data if required to do so by law or in response to a valid court order, subpoena, or government request. Where permitted, we will notify you before disclosing.
In the event of a merger, acquisition, or sale of all or substantially all of Signal Loom, Inc.'s assets, your data may be transferred to the successor entity. We will provide notice of such a transfer and of any material change in data handling practices.
We may disclose data when we believe disclosure is necessary to protect the rights, property, or safety of Signal Loom, Inc., our users, or the public.
We retain data for the following periods:
Submitted Data and Scan Results: 30 days from scan completion. Deleted from production systems thereafter. Backup copies may persist up to 90 days.
Account Information: For the duration of your account, plus 12 months following account closure to support dispute resolution and legal compliance.
Usage and Technical Logs: 90 days in production; up to 12 months in archived logs.
Communications: Up to 3 years for customer support records.
You may request earlier deletion of your data by contacting legal@signal-loom.ai. We will fulfill deletion requests within 30 days except where retention is required by law.
Subject to applicable law, you may have the following rights with respect to your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate or incomplete data.
Deletion: Request deletion of your data ('right to be forgotten'), subject to applicable legal retention requirements.
Portability: Request your data in a structured, machine-readable format.
Restriction: Request that we restrict processing of your data in certain circumstances.
Objection: Object to processing based on our legitimate interests.
Opt-Out of Marketing: Unsubscribe from marketing communications at any time using the link in our emails or by contacting us.
To exercise any of these rights, email legal@signal-loom.ai with the subject line 'Privacy Request.' We will respond to your request without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay. (Article 12(3) GDPR.) We may verify your identity before processing requests.
If you are located in the EEA or UK and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Signal Loom, Inc. implements commercially reasonable security measures, including:
Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
Strict access controls and role-based permissions for Signal Loom, Inc. personnel
Credential scanning inputs processed in isolated, ephemeral compute environments
Regular security assessments and vulnerability management
Despite these measures, no system is completely secure. You should limit the permissions of any credentials you provide to the minimum necessary for the scan (read-only access is strongly recommended). We encourage you to report any suspected security vulnerabilities to security@signal-loom.ai.
Where we transfer your personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States or any other country outside the EEA, we ensure that an appropriate transfer mechanism applies.
Standard Contractual Clauses. We rely on the European Commission's Standard Contractual Clauses (SCCs) as updated in Commission Implementing Decision (EU) 2021/914, Module 2 (Controller-to-Processor), as the primary safeguard for transfers to our service providers in the United States.
Transfer Impact Assessment (TIA). For each material transfer destination, we conduct a Transfer Impact Assessment evaluating: (a) the laws and practices of the recipient country, (b) the contractual, technical, and organizational supplementary measures applied, and (c) the practical risks to the transferred data. The TIA is reviewed at least annually and following any material change in destination-country law.
Access to documentation. A copy of the SCCs we use, and a summary of our most recent TIA, is available on request to hello@signal-loom.ai.
EU-US Data Privacy Framework (DPF). Signal Loom, Inc. intends to self-certify under the EU-US Data Privacy Framework. This Policy will be updated to reflect certification status when it is in place.
Our web interface uses cookies and similar tracking technologies to:
Maintain session state and authentication
Remember your preferences
Analyze usage patterns (using anonymized analytics)
We do not use third-party advertising cookies. Strictly necessary cookies (for session state and authentication) are used without consent because they are essential to deliver the Service. For all non-essential cookies and similar technologies, including analytics, we obtain your prior, freely given, specific, and informed consent through a consent banner before any such cookie is placed, and you may withdraw or change your choices at any time through the cookie-settings control. Non-essential cookies are not set unless and until you consent. We also honor browser-level Do Not Track signals for non-essential analytics. Refusing non-essential cookies will not prevent your use of the core Service.
Signal Loom's services are not directed to children. We do not knowingly collect personal data from anyone under the age of 16, or such higher minimum age as may be required by applicable local law (for example, France requires a minimum age of 15).
If you become aware that personal data of a person under the applicable minimum age has been provided to us without verification of parental consent, please contact hello@signal-loom.ai. We will delete the data promptly upon discovery.
The Service may contain links to third-party websites or integrate with third-party platforms. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you use in connection with the Free Scan.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised Policy on signal-loom.ai and, where feasible, by email. Your continued use of the Service after the effective date of a revised Policy constitutes acceptance of the changes.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, 'CCPA/CPRA'), provides you with specific rights regarding your personal information. This section describes those rights and how to exercise them.
Your CCPA/CPRA rights include:
Right to know — the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting it, and the categories of third parties with whom we share it.
Right to delete — request deletion of personal information we have collected from you, subject to certain exceptions.
Right to correct inaccurate personal information.
Right to opt out of the sale or sharing of personal information. Signal Loom, Inc. does not sell or share personal information as those terms are defined under CCPA/CPRA.
Right to limit the use and disclosure of sensitive personal information.
Right to non-discrimination for exercising your CCPA/CPRA rights.
To submit a request, or to designate an authorized agent to make a request on your behalf, California residents can submit requests via hello@signal-loom.ai.
We will respond to a verifiable consumer request within 45 days of receipt. We may extend the response period by an additional 45 days where necessary, with notice.
Signal Loom, Inc. does not sell or share personal information. The 'do not sell or share my personal information' right therefore requires no affirmative opt-out action, but you may contact us at hello@signal-loom.ai to confirm.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after we become aware of the breach, in accordance with Article 33 GDPR.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected data subjects directly, without undue delay, in accordance with Article 34 GDPR. Notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the contact point for further information, the likely consequences, and the measures taken or proposed to address the breach.
Internal breach response procedures, including the 72-hour notification path, are documented in our internal Incident Response Policy.
Signal Loom, Inc.'s processing activities, evaluated at our current scale, do not require the designation of a Data Protection Officer under Article 37 GDPR (the activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor do they include processing of special categories of personal data or data relating to criminal convictions on a large scale).
For all data protection inquiries, please contact us at hello@signal-loom.ai. We will respond as described in Section 8 (Your Rights).
Signal Loom, Inc. commits to reviewing this position at least annually and upon any material change in its processing activities. If a DPO designation becomes required, this Policy will be updated and the DPO's contact details published in this section.
For privacy questions, data access requests, or to report a privacy concern:
Email: legal@signal-loom.ai
Website: signal-loom.ai
Subject line: Privacy Request
We are committed to resolving privacy concerns promptly and in accordance with applicable law.