CreationLoop

[ SECURITY ]

Security at CreationLoop

CreationLoop is an early stage company. This page states only what is true today and is updated as our security program matures. Nothing is displayed as complete before it happens.

IDENTITY AND VERIFIABILITY

Our operator identity is DNS verified against creationloop.ai and published in our public agent registry at /verified/registry/. Every published production run is sealed into a tamper-evident record with SHA-256 digests anyone can recompute in their own browser, live at /verified.

ACCESS CONTROL

Production deployment and repository merge rights are held solely by the founder. Automated builders operate under least privilege: time-limited, read-only tokens scoped to a single workspace. Credentials live as environment secrets, never in code or version control.

CHANGE CONTROL

No change reaches production without human review. Published record artifacts are verified byte-exact against SHA-256 receipts before and after deployment, and commits are inspected before any production push.

HUMAN OVERSIGHT OF AGENTS

Agent-produced content passes human approval gates before publication. Every agent run carries an enforced spend cap.

DATA HANDLING

Our public proof surfaces contain no customer data. We do not use customer data in development or demonstration environments.

RESPONSIBLE DISCLOSURE

Report security concerns to marino@creationloop.ai. We acknowledge good-faith reports promptly.