Following the completion of its SOC 2 Type I audit, Looki is entering the next phase of its privacy and security work.
Protecting our users’ privacy and the security of data is a core priority at Looki.
Privacy and security are not one-time checkpoints for us, but an ongoing part of how we build, operate, and improve Looki as the product continues to grow.
01
Completed
SOC 2 Type I
Looki has completed an independent SOC 2 Type I audit of the security controls supporting its systems and services. This provides a foundation for the compliance work now underway.

02
In Progress
SOC 2 Type II
Looki is now working toward SOC 2 Type II, which will evaluate whether relevant controls operate effectively over a defined review period.
ISO/IEC 27001
Looki is developing an Information Security Management System in preparation for ISO/IEC 27001, the international standard for managing information security risks and controls.
ISO/IEC 27701
Alongside ISO/IEC 27001, Looki is working toward ISO/IEC 27701 to further formalize how personal information and privacy responsibilities are managed.

03
Next Priorities
The next priorities will extend this work to privacy and sensitive data requirements in key markets.
GDPR Alignment
Looki has established processes supporting individual privacy rights and international data transfers, while its broader GDPR alignment program continues.
CCPA/CPRA Readiness
Looki has published a California privacy addendum and provides mechanisms for users to submit requests concerning data sale or sharing and the use of sensitive personal information, with broader CCPA/CPRA readiness work continuing.
HIPAA Readiness
Looki has begun assessing and developing safeguards relevant to potential HIPAA-regulated use cases involving health information.

Together, these initiatives define the next stage of Looki’s privacy and security work. Further updates will be shared as we reach our next milestones.
0 comments