KordLoom

Vendor review

Who you would be contracting with, what happens to your install if this company stops, and the answers a security questionnaire asks.

kordloom.com · Vendor review

Vendor review

What a security or procurement review asks about KordLoom LLC, answered here. Last reviewed September 2026.

The company

KordLoom LLC is a Texas limited liability company. It builds and sells self-hosted infrastructure software: SwitchTender, a governed execution boundary for infrastructure change, and LoomSeal, the open evidence format underneath it.

The software runs on your machines. A paid tier unlocks features already present in the binary you downloaded, verified against a signed license file with no license server and no call home. Operated services and paid support are sold separately, and both are opt-in.

If the company stops

Your install keeps running. It needs no license server, no activation, and no network connection to KordLoom, so nothing expires when the company does.

Your evidence stays verifiable. Receipts and bundles are checked by an open verifier under Apache 2.0, against a published format with conformance vectors and an independent Python implementation. Nothing in that path involves KordLoom.

The source outlives the company. SwitchTender is source-available under BSL 1.1, and each release converts to Apache 2.0 two years after it ships, by a term written into the license rather than by anyone deciding to honor it. You can mirror the repository today and keep mirroring it.

What ends with the company are the operated services: hosted witness countersignatures, evidence custody, scheduled delivery of evidence packs, and support. Each has a self-service equivalent in the free binary.

Security review

SwitchTender publishes its vendor risk review already answered, in the order reviews ask: where it runs and what data leaves, authentication and access, secrets handling, change control and audit, supply chain, vulnerability management, data retention and portability, and subprocessors.

At the company level: there is no telemetry, no usage reporting, and no update check in any product. The self-hosted software has no subprocessors, because no data reaches KordLoom. Releases are signed, checksummed, and carry build provenance.

Contact

Security reports go to [email protected], not to a public issue. The published policy is acknowledgment within a few business days and a patched release on the current line once a fix is ready.

Licensing, procurement, and everything else: [email protected].

Checking it yourself

Each of these is readable without asking:

If something here is wrong, say so at [email protected] and it gets corrected.