Stay in control of AI across your whole company
Control all your data, connected tools, and agents.

Security and trust, built for the agentic era



Certifications and assessments
We are SOC 2 Type II attested and HIPAA compliant, and we offer BAAs for eligible plans. We hold our own code to the highest security bar, using industry-leading tooling on Gumloop itself, and emerging threats and upstream patches are triaged and remediated quickly.

Privacy and how your data is used
We have zero data retention (ZDR) agreements with major large language model providers. You choose which models and providers your agents use, and you can bring your own keys (BYOK) so calls run through your own provider accounts.
Compliance and data handling
We maintain a GDPR-aligned privacy program and are certified under the EU-U.S. Data Privacy Framework, including the UK Extension. DPAs are available upon request for Enterprise customers.
Access and infrastructure
Data is encrypted in transit and at rest. Connect any identity provider for single sign-on (SSO) and automated user provisioning with SCIM.

Deployment you control
Run Gumloop as managed SaaS, or deploy into your own cloud (VPC), in the region of your choice. Your data stays in the infrastructure you control.

Governance for agents and MCP
Control what your agents and tools can do: role- and attribute-based access, per-tool authorization, full traceability for every tool call, and a live inventory of every MCP server in use. Secrets are managed centrally, and never sit in plaintext on someone’s laptop.
Deep governance for every agent and MCP server
Learn more about agent and MCP governance with Gumstack.

Tool call traceability
Every call is tied to a specific user, agent, or service principal with full traces.
Per-tool authorization
Authorize different access levels for different types of tools by setting per-tool policies.
Secrets that don’t live on laptops
No local plaintext keys, no mystery config files. Enforce credential flows, handle rotation and revocation, and plug into your existing vault.

MCP inventory and auditing
See every MCP client and server, local or remote, in one place. Spot unauthorized MCPs before they become a risk.