[ SECURITY ]
Security at CreationLoop
CreationLoop is an early stage company. This page states only what is true today and is updated as our security program matures. Nothing is displayed as complete before it happens.
IDENTITY AND VERIFIABILITY
Our operator identity is DNS verified against creationloop.ai and published in our public agent registry at /verified/registry/. Every published production run is sealed into a tamper-evident record with SHA-256 digests anyone can recompute in their own browser, live at /verified.
ACCESS CONTROL
Production deployment and repository merge rights are held solely by the founder. Automated builders operate under least privilege: time-limited, read-only tokens scoped to a single workspace. Credentials live as environment secrets, never in code or version control.
CHANGE CONTROL
No change reaches production without human review. Published record artifacts are verified byte-exact against SHA-256 receipts before and after deployment, and commits are inspected before any production push.
HUMAN OVERSIGHT OF AGENTS
Agent-produced content passes human approval gates before publication. Every agent run carries an enforced spend cap.
DATA HANDLING
Our public proof surfaces contain no customer data. We do not use customer data in development or demonstration environments.
RESPONSIBLE DISCLOSURE
Report security concerns to marino@creationloop.ai. We acknowledge good-faith reports promptly.
