openloops

Data Security

Last updated: September 30, 2026

Our Approach to Security

openloops is open-source and self-hosted. That shapes how security works today: instead of us holding your application's data on your behalf, openloops runs inside your own infrastructure, using your own database.

This page explains how security works for the framework as it exists today. As openloops grows to offer a hosted, managed option, this page will be updated to describe the additional protections and commitments that come with it.

How Security Works Today

Open source, auditable by design

The full source code of openloops is public on GitHub under the Apache License 2.0. Anyone can read, audit, and verify exactly what the framework does, rather than relying on our word for it.

You control your own data

When you build an agent with openloops, chat history, tasks, and context are stored in your own MongoDB database, inside your own infrastructure. openloops does not transmit that data to us. Its security, backups, and access controls are your responsibility as the operator, the same as with any self-hosted software.

Sensitive credentials are encrypted

Sensitive values that openloops itself manages, such as headers and credentials for connected MCP servers, are encrypted using a secret key you configure and control. openloops never stores this key, or your data, on our own servers.

Dependencies are kept current

We track and update the framework's dependencies to address known vulnerabilities as they're disclosed upstream. As with any Node.js project, we recommend running your own dependency audits as part of your deployment process.

Reporting a Security Vulnerability

If you believe you've found a security vulnerability in openloops, please report it privately before disclosing it publicly, so we have a chance to address it. Email us at jose@openloops.xyz with details and, if possible, steps to reproduce the issue.

Looking Ahead

As openloops introduces a hosted, managed offering for teams that don't want to self-host, additional security practices, data-handling commitments, and compliance details will apply to that offering specifically. We'll expand this page with those details as they become real, rather than in advance of them.

Questions about security?

jose@openloops.xyz