Northloop Security Check

Privacy & testing policy

Northloop Security is a service of Northloop, a London-based UK sole trader. This page explains how we handle your data and how we test, in plain English.

What we test

We only ever test assets you own and have authorised us to test. For free scans, that is the single domain you submit through the scan form, and only from the outside: we do not log in, we do not touch internal systems, and we exclude any check that could affect availability. Paid engagements are covered by a written authorisation setting out exactly what is in and out of scope.

What we collect

The details you submit (business name, domain, email), whether through the free-scan form or the result screen of the instant domain check, and the technical findings from scanning your public-facing infrastructure. We use this only to produce and discuss your report. The instant domain check itself captures nothing: it reads public DNS records for the domain you type and shows the result in your browser.

How we store it

Findings are confidential and shared only with you and anyone you ask us to brief. We never contact your clients. We do not sell or share your data, and we never use your findings in marketing; the only figure we publish is an aggregate spoofing statistic across a public register, which names no firm. You can ask us to delete your data at any time by emailing security@northloopsystems.com.

Your rights

Under UK GDPR you can request access to, correction of, or deletion of your data. We respond within 30 days. Our terms of service set out what we do and do not do on an engagement.