Security & trust
Let AI agents do real client work—without handing over your credentials.
Outloop is a local-first access layer for teams running AI agents across many client systems. Agents work through connections you approve, and the raw credentials are never handed to the agent, the chat, or the work it produces.
- Agents work through connections you approve
- Raw credential values are never returned to the agent
- You grant, review, and remove access at any time
Last updated:
In short
Outloop lets AI agents use client systems through connections you approve, without receiving the raw credentials.
Access is set up once per client workspace and scoped to the systems and permissions you choose. Agents work through those approved connections; sensitive credential values are not returned to them. Activity is recorded, sensitive output is redacted, and access can be reviewed or removed at any time.
Real work, not a read-only demo
Outloop does not reduce every connection to a read-only demo. Agents can do the work the job actually needs, inside the access you approved.
Security is the control layer. The outcome is running more client workflows without rebuilding access every time.
How it works, at a high level
-
Your agent
Asks Outloop to do something in a client system.
-
Outloop-controlled access
Uses the connection you approved for that workspace.
-
Customer-approved service
The system you connected, through its official API.
What Outloop controls
-
Approved connections, not shared secrets
Agents work through connections you approve. Raw credential values are not returned to the agent, the chat, or the work it produces.
-
Scoped per workspace and per system
Access is controlled for each client workspace and each connected system. A new workspace starts with no access until you grant it.
-
Permissions you choose
Connections use each provider’s official API and OAuth flows. You decide which permissions and administrative consent to grant.
-
Recorded activity, redacted output
Activity is recorded, and sensitive values are removed from what the agent can see.
Where each kind of data is handled
| Data | Where it is handled | Outloop Cloud | Agent visibility |
|---|---|---|---|
| Raw API credentials and OAuth tokens | Secure storage on the machine you control | Not stored | Never returned |
| Work done through an approved connection | Your machine and the service you approved | Not stored by Outloop Cloud | Approved, redacted results only |
| Activity records | The machine you control | Not stored | Redacted views only |
| Account, trial, billing, licensing, onboarding, activation | Outloop Cloud | Service metadata only | No customer API credentials |
| Workspace and access identifiers | Where required for identity and entitlement | Identifiers only | No credential values |
Full detail on website, account and billing data is in the privacy policy.
You stay in control
Nothing grants itself access. A person decides what each client workspace can reach, and can withdraw it at any time.
- Choose which systems each client workspace can reach
- Choose the permissions each connection is granted
- Review activity for a workspace
- Remove access at any time, without ever handling the credential
A read-only connection is a safe way to start. Broader access is granted only when you decide to grant it.
Connecting to the systems you already use
Outloop connects through official provider APIs and OAuth flows where applicable. You control the permissions and administrative consent granted by each provider.
Which systems are connected, and what each one may do, is set per client workspace. The published setup guides cover the services we have documented.
Outloop works alongside your password manager
Outloop is not a replacement for a password manager or vault. It adds the layer you need when AI agents — not people — are doing the work: approved access per client, recorded activity, and redacted output.
More on that boundary: Outloop is not a vault.
Build integrity and current limits
The Outloop Mac app is signed with an Apple Developer ID, runs under the hardened runtime, and is notarized and stapled by Apple, so macOS Gatekeeper accepts it as a notarized Developer ID application.
Outloop is an actively developed product available with guided onboarding. Do not treat it as independently certified security infrastructure. Here is what we do not claim:
- No SOC 2, ISO 27001, GDPR or HIPAA certification
- No formal third-party penetration testing
- No enterprise SSO or SCIM provisioning
- No published breach-response SLA and no data-residency guarantee
- No immunity to prompt injection, and no claim of complete prevention of every possible wrong-client action
If a claim is not written on this page, treat it as not claimed. We would rather answer a questionnaire honestly than publish a badge we have not earned.
Preparing a formal security review?
We respond directly to security questionnaires based on current, verified product behavior. Additional detail is shared with qualified reviewers on a need-to-know basis, and deeper material is provided under NDA where appropriate.
Book a security walkthroughResponsible use
Outloop is intended only for API credentials, accounts, workspaces, systems, and data that you own, manage, or are legally authorized to access. It must not be used for unauthorized access, credential theft, spyware, keylogging, account takeover, spam, abuse, or unlawful activity.
Security contact and disclosure
For security questions or responsible disclosure, contact
support@outloop.co.
Please do not include raw API keys, passwords, bearer tokens, authorization headers,
.env contents,
or customer secrets in your report.
Questions reviewers ask first
Give agents the access they need—without giving them the credentials.
Create your trial. Download the Mac app. Run your first approved connection.