Security at Demoloop
Effective June 20, 2026
Operator
Demoloop is managed by Vantar Group LLC, Wyoming.
Organization and surface isolation
Authenticated workspace access and publishable widget keys scope product configuration, approved knowledge, sessions, calls, and analytics to the owning surface. Organization membership controls which surfaces a team can manage.
Data protection
Production traffic and signaling use TLS. Provider credentials remain server-side, CRM tokens are encrypted before persistence, and signed webhooks allow customers to verify handoff authenticity.
SDK controls
The SDK uses exact message origins, domain-validated surface keys, a versioned protocol, bounded context, explicit host actions, action timeouts, cancellation, and server-side sanitization. String navigation actions remain on the host origin.
Voice and video
Camera and microphone access require browser permission. Expert video calls use encrypted browser WebRTC media sent peer-to-peer and are not recorded by Demoloop. Room-scoped tokens and signaling metadata authorize and establish the connection; expired rooms reject new signaling.
Application controls
Demoloop applies rate limits to public AI and call endpoints, domain restrictions to published widgets, explicit visitor-consent controls, configurable retention, outbound PII redaction, and workspace audit history.
Operational security
Authentication is provided through Clerk, data is stored in Neon Postgres, and production workloads run on Vercel. Monitoring hooks are included to capture operational failures without intentionally sending default personal information.
Responsible disclosure
If you believe you found a vulnerability, email security@getdemoloop.com with reproduction steps and potential impact. Please avoid accessing data that is not yours.