Skip to main content
Languages

Verify a TradinLoop Secure Link

This page explains how to verify document-access and quotation-submission links issued by TradinLoop.

TradinLoop uses WorkDrive to distribute RFQ documents and receive files from authorised stakeholders. TradinLoop WorkDrive links are open-access links and do not require the recipient to create an account or authenticate.

Last updated: 31 July 2026


1. Official TradinLoop WorkDrive domain

Every legitimate TradinLoop WorkDrive link begins exactly with:

https://workdrive.tradinloop.com/

Additional characters will normally appear after the final /. These characters identify the specific folder, document collection or file-sharing location.

Example format:

https://workdrive.tradinloop.com/[unique-link-reference]

The relevant security check is the actual domain shown in the browser address bar:

workdrive.tradinloop.com

A legitimate TradinLoop WorkDrive link will not redirect you to a page asking for:

  • a username or password;

  • your corporate email password;

  • a one-time authentication code;

  • payment-card or banking information;

  • installation of software;

  • installation of a browser extension; or

  • remote access to your computer.

If any such request appears, stop immediately and contact TradinLoop through a previously verified communication channel.

2. How to inspect a link before opening it

Before selecting a document link:

  1. Hover over the link and inspect the actual destination displayed by your email application or browser.

  2. On a mobile device, press and hold the link to preview or copy the destination.

  3. Confirm that the address begins exactly with:

    https://workdrive.tradinloop.com/

  4. Check that there are no additional words, characters or domains before or after tradinloop.com.

  5. Do not rely solely on the displayed link text, email branding, logo, HTTPS padlock or wording of the message.

  6. Do not proceed if the displayed address and the actual destination are different.

Examples of addresses that are not official TradinLoop WorkDrive domains include:

  • https://workdrive-tradinloop.com/

  • https://tradinloop-workdrive.com/

  • https://workdrive.tradinloop.com.example.com/

  • https://workdrive.tradinIoop.com/

  • https://example.com/workdrive.tradinloop.com/

A domain that merely contains the words “TradinLoop” or “WorkDrive” is not sufficient.

3. Open-access links and confidentiality

TradinLoop WorkDrive links provided to RFQ stakeholders are open-access links.

This means:

  • the recipient does not need an account;

  • no authentication is required;

  • possession of the complete link may permit access to the shared location; and

  • the complete link should therefore be treated as confidential.

Recipients must not:

  • publish the link;

  • post it on social media;

  • forward it to unauthorised persons;

  • paste it into a public discussion forum;

  • submit it to an unapproved public URL scanner; or

  • include it in publicly accessible documents.

The link should be shared internally only with persons authorised to participate in the relevant RFQ or transaction.

If a link has been disclosed to an unauthorised person, notify TradinLoop promptly so that it can be revoked and replaced.

4. Independent technical assessment

Before issuing an RFQ link, TradinLoop may assess the link using the independent Cloudflare Radar URL Scanner.

Cloudflare Radar can review technical information associated with a URL, including:

  • the submitted destination;

  • redirects;

  • contacted domains and IP addresses;

  • TLS certificates;

  • page technologies and behaviour;

  • phishing or malicious-content indicators;

  • files automatically downloaded during the scan; and

  • an overall malicious-content verdict where sufficient information is available.

The Cloudflare Radar URL Scanner is available at:

Cloudflare Radar URL Scanner

Important instruction for recipients

Do not paste the complete TradinLoop RFQ link into Cloudflare Radar or another public scanning service.

Because TradinLoop WorkDrive links are open-access links, submitting the complete URL to a third-party scanner may disclose the access-bearing link to that service or to other parties.

Recipients who wish to perform an independent domain-level check may scan only the public base address:

https://workdrive.tradinloop.com/

TradinLoop may separately provide the recipient with:

  • a PDF copy of the Cloudflare Radar assessment for the exact RFQ link;

  • the assessment date and time;

  • the status displayed by Cloudflare;

  • confirmation of the observed destination; and

  • the relevant RFQ reference.

5. Test the public TradinLoop WorkDrive domain

The public TradinLoop WorkDrive domain may be submitted to the following independent services:

Cloudflare Radar URL Scanner

Use: https://radar.cloudflare.com/scan

Enter only: https://workdrive.tradinloop.com/

Do not add the unique folder, file or collection reference.

Google Safe Browsing site-status check

Use: Google Safe Browsing Site Status

Enter only: workdrive.tradinloop.com

These services provide independent technical or reputation information about the domain. They do not provide a permanent guarantee that every link, document or future page is free from risk.

6. Meaning and limitations of a URL assessment

A URL scan is a point-in-time technical assessment. It is not a certificate, warranty or guarantee that a link is completely safe.

A scan may determine whether:

  • known malicious behaviour was detected;

  • the domain is associated with known phishing activity;

  • the TLS certificate is valid;

  • the page contacts unexpected domains;

  • unexpected redirects occur; or

  • an unexpected file is downloaded automatically.

A scan does not necessarily establish that:

  • every document available through the link is harmless;

  • the link will remain unchanged;

  • the link has not been forwarded;

  • the recipient’s device or email account is secure;

  • no previously unknown malware is present; or

  • the link will remain valid after the assessment.

Where Cloudflare displays No classification, this does not mean that Cloudflare has certified the URL as safe. It means that Cloudflare did not have sufficient information to assign a malicious classification.

TradinLoop therefore reviews both the scan result and the observed behaviour of the link.

7. WorkDrive safeguards

Zoho states that WorkDrive applies security controls including:

  • encryption of data during transmission;

  • encryption of files at rest;

  • granular sharing and access controls;

  • link-expiry and revocation controls;

  • activity tracking and audit records;

  • malware and virus checking;

  • infrastructure monitoring;

  • backup and disaster-recovery arrangements; and

  • independently assessed security and compliance controls.

Further information is available from:

These controls reduce cyber, confidentiality and unauthorised-access risks. They cannot eliminate every risk associated with internet communications, compromised email accounts, user error, unauthorised forwarding, incorrectly configured permissions or previously unknown malware.

8. What a TradinLoop WorkDrive link will not request

A legitimate TradinLoop WorkDrive link will not require you to:

  • sign in to an account;

  • provide a password;

  • provide your email password;

  • disclose a one-time authentication code;

  • install remote-access software;

  • install an unrelated application or browser extension;

  • disable antivirus or endpoint protection;

  • provide payment-card information;

  • make a payment to access RFQ documents; or

  • transfer funds to verify your identity.

A file-upload page may request ordinary submission information such as:

  • your name;

  • company name;

  • business email address;

  • RFQ reference;

  • filenames; and

  • supporting comments.

It should not request authentication credentials.

9. Unexpected redirects or requests

Stop immediately if:

  • the browser leaves the workdrive.tradinloop.com domain unexpectedly;

  • a login page appears;

  • credentials are requested;

  • a browser security or certificate warning appears;

  • software installation is requested;

  • an executable file downloads automatically;

  • the page contains unrelated advertising;

  • the page refers to an RFQ or transaction that you do not recognise; or

  • the link was received from an unverified sender.

Do not continue merely because the page displays a TradinLoop logo.

10. How to verify a specific link with TradinLoop

If you have any doubt, do not open the link and do not forward it to another person.

Verify it through a separate communication channel by:

  • replying to the original TradinLoop RFQ email;

  • contacting the known TradinLoop representative through previously verified contact details; or

  • using the TradinLoop Contact page.

When requesting verification, provide:

  • the sender’s email address;

  • the RFQ reference;

  • the date and time the message was received;

  • the visible link text;

  • the actual destination obtained by hovering over or copying the link; and

  • a screenshot of the message, where possible.

TradinLoop may confirm whether:

  • the sender is authorised;

  • the link was issued by TradinLoop;

  • the link is still active;

  • the destination corresponds to the stated RFQ; and

  • a third-party assessment report is available.

11. Reporting a disclosed or suspicious link

Notify TradinLoop promptly if:

  • the link was sent to the wrong recipient;

  • the link was forwarded outside the authorised organisation;

  • the link was posted publicly;

  • an unexpected person accessed the documents;

  • the browser displayed a warning;

  • the page requested credentials;

  • the link redirected to another domain; or

  • suspicious files or behaviour were observed.

TradinLoop may revoke the affected link, issue a replacement and review the corresponding access records.

12. Shared responsibility

TradinLoop applies controlled sharing, link assessment, access monitoring and revocation measures.

Recipients remain responsible for:

  • protecting the complete access link;

  • restricting internal circulation;

  • maintaining updated browsers and endpoint protection;

  • verifying the sender;

  • observing internal authorisation procedures;

  • reporting suspicious behaviour; and

  • avoiding disclosure of the link to public scanning or collaboration services.

Security is a shared responsibility between Zoho, TradinLoop and each participating organisation.