Security policy
We take security seriously here at Overloop, and we are proud to exceed the industry standard when it comes to protecting your organization.
Explore our Security Report here



Infrastructure
All of our services run in the cloud. We don’t host or run our own routers, load balancers, DNS servers, or physical servers. Our service is built on Heroku (Salesforce, Inc.) which itself is hosted on Amazon Web Services (AWS). They provide strong security measures to protect our infrastructure and are compliant with most certifications. You can read more about their practices here and here.
Security Features
- A WAF is set up to filter incoming requests trying to compromise the service.
- A firewall is systematically used on Overloop’s servers to prevent access from non-approved IP addresses.
- Critical admin interfaces are protected using at least double-authentication.
- Our software infrastructure is regularly update using automatic update mechanisms when possible.
- End-to-end encrypted messaging systems are available to Overloop’s employees and contractors, and used for most communications.
Vulnerability disclosure program
No technology is perfect, and we believe that working with skilled security researchers across the globe is crucial in identifying weaknesses in Overloop. If you believe you’ve found a security issue in our product, we encourage you to notify us and welcome working with you to resolve the issue promptly.
Have further questions about our Security Policy?