| Version | Supported |
|---|---|
| 0.4.x | ✅ |
| 0.3.x | ❌ |
| < 0.3 | ❌ |
If you discover a security vulnerability, please:
- Do NOT open a public issue
- Email security@loop-engineering.dev with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will respond within 48 hours and work with you to address the issue.
When using Loop Engineering:
- Budget Caps: Always set budget limits
- Checkpoints: Use conservative checkpoint presets for sensitive operations
- Gates: Enable security gates
- Secrets: Never commit API keys
- Scope: Limit file system access
Loop Engineering includes:
- Budget enforcement (prevent token blowout)
- Human checkpoints (prevent unauthorized actions)
- Deterministic gates (catch issues before LLM calls)
- Worktree isolation (prevent unauthorized file access)