Security overview / updated September 17, 2026

Your dossier is product data, not public content.

ChangeLoop 7 keeps customer records behind authenticated account boundaries and limits model use to specific analysis checkpoints. This page describes current controls without claiming a certification the product does not hold.

How does ChangeLoop 7 protect customer data?

Production account, session, dossier, workflow-receipt, and provider configuration records are stored server-side with encryption controls. Browser sessions use secure cookies, and model credentials are never returned to the customer interface.

Current controls

Security is applied at the workflow boundary.

Authenticated ownership

An account can access only its own dossier. The server checks identity and the legal workflow state before accepting analysis or dossier changes.

Bounded model disclosure

Only the context needed for a fixed analysis step is sent to configured model providers. The complete lifetime archive is not placed into every prompt.

Replay protection

Analysis checkpoints use idempotency and workflow locks so a refresh or retry does not intentionally create duplicate model work or overwrite completed history.

Temporary browser copy

The active tab keeps a temporary session-storage copy for interface recovery. The product clears it on sign-out or account deletion and does not describe browser storage as encrypted. The encrypted server dossier remains authoritative.

Customer control

Customers can export a portable dossier and request permanent account deletion through the product controls, subject to the published privacy and retention terms.

Honest limitation

No online service can promise zero risk.

ChangeLoop 7 does not currently claim SOC 2, ISO 27001, HIPAA, or clinical-system certification. Customers should not enter passwords, financial account data, medical records, government identifiers, or emergency information into behavioral reflections.

Report a concern

Security and privacy contacts

For a suspected security issue, contact support@changeloop7.com. For personal-data questions, contact privacy@changeloop7.com. Include the affected page or account email, but never send a password or API key. The machine-readable disclosure contact is published at /.well-known/security.txt.