Trust
Security
Last updated: 29 September 2026
Loam moves money between businesses across borders. Every organisation is verified before it can send or withdraw funds, and activity is monitored. This page summarises how we protect counterparties, funds, data, and infrastructure. For a shorter overview, see the security overview.
Verified counterparties
Every organisation on Loam must pass KYB verification, including sanctions screening, before it can send or withdraw funds. Destination wallet addresses are screened before funds are sent on-chain, and payments are monitored.
Custody of funds
Balances are held in stablecoins, currently USDC, in wallets that we maintain with our custody provider. Loam does not keep fiat balances for you: fiat you send is received through partner banks or payment providers and converted into your stablecoin balance, and fiat payouts are made through them.
Encryption
Data is encrypted in transit (TLS) and at rest (AES-256). Backups are encrypted and stored in access-controlled object storage. Secrets are held in managed key-management services, never in source code.
Access controls
Least-privilege access to production systems and data. Access is authenticated, logged, and monitored; privileged actions require additional controls. Wallet and signing operations are protected by KMS-backed key custody.
Payment monitoring
Payments are monitored to help detect financial crime, and potential issues are raised as cases for review. Every action, settlement, and invoice is timestamped and linked for a complete audit trail.
Infrastructure
Loam runs on hardened cloud infrastructure with network isolation, regular patching, and immutable, append-only event records for sensitive aggregates.
Compliance
We operate under EU/UK GDPR and applicable AML and trade regulations. See the Privacy Policy for data handling. We are working toward SOC 2 certification.
Responsible disclosure
If you believe you have found a security vulnerability, email security@loampay.com with enough detail to reproduce it. Please give us a reasonable window to investigate and remediate before any public disclosure, and do not access, modify, or exfiltrate data that is not yours while testing. A formal vulnerability disclosure policy is in preparation.
Contact
Security questions: email security@loampay.com.