90 Days Gen AI Risk Trial -Start Now
Book a demo
Productivity·Free (25 videos); Business $15/creator/mo; Enterprise custom·loom.com

Loom AI

Loom AI, now owned by Atlassian, is an async video messaging tool that records screen and camera and uses AI to auto-title, summarize, chapter, and transcribe videos for sharing across teams.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Loom is Atlassian's async video messaging platform for work, letting employees record screen-and-camera videos that are shared via link and embedded in tools like Jira, Confluence, Slack, and Notion. Loom AI adds generative features on top: automatic titles, summaries, chapters, task extraction, transcripts, and filler-word removal, so viewers get structured takeaways without watching every minute. Under Atlassian, Loom inherits the Atlassian Trust program: SOC 2 Type I (with Type II on roadmap per public posts), ISO 27001, GDPR compliance, SSO and SCIM via Atlassian Access, DPA availability, and reports accessible through the Atlassian Trust Center. Loom is explicitly not HIPAA compliant and does not sign BAAs, so it should not be used for PHI. Business and Enterprise tiers add admin controls, domain capture, content deletion policies, and granular sharing restrictions.

Risk factors

3
  • Processes user-generated video content
  • Data may be stored on third-party servers
  • Limited transparency on data retention policies

Recommendations

2
  • Ensure compliance with data protection regulations
  • Consider self-hosted alternatives if available

Data handling

Storage
Videos, transcripts, and AI-generated metadata stored on Atlassian-managed cloud infrastructure; access controlled via workspace and share settings.
Retention
Content retained while account is active; admins on Business/Enterprise can configure auto-delete and deletion workflows; deleted content purged per Atlassian policy.
Training on inputs
Atlassian states customer content is not used to train third-party foundation models; Loom AI features process content under contractual no-train terms with providers.