Executive Summary
AI-generated analysis for Loom
Loom (loom.com), a widely adopted screen recording and video messaging platform acquired by Atlassian, presents a Low Risk (Tier 4) profile based on independently sourced evidence gathered during this investigation. Several positive signals support this assessment:
Key Findings
- The domain has been registered since 1997 and is managed through enterprise-tier registrar MarkMonitor, indicating organizational maturity
- Domain reputation is clean across all blacklist checks (SURBL, Spamhaus DBL, URLhaus) with zero threat intelligence pulses and a 0% IP abuse score
- Infrastructure exposure is minimal: 1 open port detected with 0 known CVEs, and the site is served behind Cloudflare CDN — this represents an exceptionally controlled footprint, well below the SaaS industry average of 8–12 open ports
- TLS configuration uses TLSv1.3 with a modern cipher (AES-128-GCM-SHA256), and the certificate is valid through December 2026
- Loom explicitly commits to not training AI models on customer data, discloses OpenAI as its LLM provider for transcription, and states that neither OpenAI nor any other provider retains customer inputs and outputs
- No sanctions matches, adverse media, SEC enforcement filings, or historical adverse media were identified Two areas warrant attention prior to finalization:
- Five compliance certifications (SOC 2, ISO 27001, FedRAMP, NIST 800-53, and GDPR) are referenced on Loom's trust and privacy pages but remain vendor-attested only; ISO 27001 was not found in the IAF CertSearch registry, and FedRAMP was not confirmed in the FedRAMP Marketplace — compliance teams should request the actual SOC 2 Type II report and ISO 27001 certificate directly from the vendor
- HTTP security headers scored a C (50/100) on HTTP security scanner, with Content-Security-Policy and X-Frame-Options absent from the marketing site; while these gaps do not indicate active compromise, they represent a configuration improvement opportunity
- Loom's published subprocessor page (https://loom.com/privacy/subprocessors) could not be automatically parsed, leaving third-party data processor visibility incomplete Overall, Loom presents a well-established, low-risk vendor profile appropriate for medium data access use cases. The certification claims should be independently confirmed by requesting audit documentation directly from the vendor.
Independence Statement
All evidence in this report was independently sourced from external data providers and public registries without any participation, notification, or input from Loom.