Authenticated ownership
An account can access only its own dossier. The server checks identity and the legal workflow state before accepting analysis or dossier changes.
Security overview / updated September 17, 2026
ChangeLoop 7 keeps customer records behind authenticated account boundaries and limits model use to specific analysis checkpoints. This page describes current controls without claiming a certification the product does not hold.
Production account, session, dossier, workflow-receipt, and provider configuration records are stored server-side with encryption controls. Browser sessions use secure cookies, and model credentials are never returned to the customer interface.
Current controls
An account can access only its own dossier. The server checks identity and the legal workflow state before accepting analysis or dossier changes.
Only the context needed for a fixed analysis step is sent to configured model providers. The complete lifetime archive is not placed into every prompt.
Analysis checkpoints use idempotency and workflow locks so a refresh or retry does not intentionally create duplicate model work or overwrite completed history.
The active tab keeps a temporary session-storage copy for interface recovery. The product clears it on sign-out or account deletion and does not describe browser storage as encrypted. The encrypted server dossier remains authoritative.
Customers can export a portable dossier and request permanent account deletion through the product controls, subject to the published privacy and retention terms.
Honest limitation
ChangeLoop 7 does not currently claim SOC 2, ISO 27001, HIPAA, or clinical-system certification. Customers should not enter passwords, financial account data, medical records, government identifiers, or emergency information into behavioral reflections.
Report a concern
For a suspected security issue, contact support@changeloop7.com. For personal-data questions, contact privacy@changeloop7.com. Include the affected page or account email, but never send a password or API key. The machine-readable disclosure contact is published at /.well-known/security.txt.