Security

Information security at Loopfy

Version 2026-08-15Last updated 15 August 2026

Travel agencies entrust their clients’ passports to Loopfy. This page sets out the measures that protect that data. It is limited to things that are true today, and where we have not done something, this page says so rather than leaving it to be assumed.

Separation of agency data

Separation is enforced by the database itself through row-level security, not only by the application. A query for another agency’s records returns nothing, because the database refuses it regardless of what the application requests.

Document storage

Passports and every other uploaded or generated document are held in a private store with no public access. Anything shown in the product is reached through a link created on demand for the person requesting it, which expires shortly afterwards. No document has a permanent public URL, so a link cannot be forwarded or indexed and keep working.

Authentication and passwords

Sign-in is handled by our authentication provider. Loopfy never stores, sees or transmits your password, so a problem on our side cannot expose it. Connections to Loopfy are encrypted in transit.

Staff access to customer data

Administrative screens are gated on a platform-administrator check that runs before any elevated database access is opened, and no user can grant themselves that permission. Loopfy staff can reach customer records for support and diagnosis. What we hold, and who can see it, is set out in our Privacy Policy.

Data location

The main database and document store run in Amazon Web Services’ Seoul region (ap-northeast-2). The other companies involved in running Loopfy, what each one receives, and where each holds it are listed in our Privacy Policy.

Deletion

An agency can permanently delete an application and its documents from within the product, and can download its documents at any time. Because of backups, deletion is not instantaneous everywhere. Our Privacy Policy describes what deletion does and does not do.

Reporting a security problem

If you believe you have found a security problem in Loopfy, email support@loopfy.io with a description of what you found and how to reproduce it. We ask that you allow us a reasonable opportunity to remedy it before making it public.