Loom keeps your agents on track.

Security and privacy

What Loom stores, who can read it, how credentials work, and how to protect and report.

Your credentials#

~/.loom/stores.toml holds the connection details for your stores, including keys. Treat it as a credential file:

  • never commit it to Git;
  • never paste it into an issue, chat, screenshot or log;
  • do not share it between unrelated people;
  • let loom setup or loom login write it rather than assembling it by hand.

Setup writes it atomically and restricts it to your user (mode 0600 on Linux and macOS). On Windows setup removes inherited permissions and grants full control to your user only, before any secret is written. A stores.toml written by a Loom older than v0.672 can still carry read access inherited from its folder (another local account or group; one was seen on a v0.660 install). Check it with icacls %USERPROFILE%\.loom\stores.toml: a file written by v0.672 or later shows exactly one entry, your user with (F), and none marked (I). Re-run loom login to rewrite an older file, or remove inherited entries yourself. Not verified on Windows: that icacls shows one full-control entry for your user and no inherited entries on v0.672 or later; only code and a regression test confirm it.

Setup does not restrict the ~/.loom directory itself. On a default Linux install it is group-writable (mode 0775) and only stores.toml is 0600. On a shared machine, run:

chmod 700 ~/.loom

Email codes, sign-in links and enrollment grants are short-lived. Codes last 10 minutes and are single-use. Enter them only at the hidden prompt, and confirm you started the request yourself before following any sign-in link.

Logging out#

loom logout needs the section name; the bare command fails with missing a required argument: 'section':

loom logout --params '{"section":"<name>"}'

This removes that section from ~/.loom/stores.toml. The result's server_status: "removed" refers to the local section only; nothing is revoked on the server. If you log out of the section that default points to, stores.toml loses its default line and loom list_stores fails with `must set top-level default = "<store>" until you run loom login` again, which writes it back.

What is stored and where#

DataWhereNotes
Facts, relations, rules you saveThe store on the serverOne store per section in stores.toml.
Connection credentials~/.loom/stores.tomlYour computer only.
Embedding model files~/.loom/cache/fastembed on your computerDownloaded on first save; no facts in it.
Model download cache~/.cache/huggingface/ on your computerCreated on first save (download logs and staging); no facts in it.
Embedding runtime device id~/.cache/Microsoft/DeveloperTools/.onnxruntime/Created by the embedding runtime.
Plugin update check cache~/.loom/plugin-update-check.jsonExists only when a Claude Code or Codex plugin is installed. Holds the marketplace's latest commit and version.

Do not save passwords, tokens or other secrets as facts.

What leaves your computer#

  • Facts, queries and keys go only to your Loom server: sign-in over HTTPS on the server's web port, memory over an encrypted connection on the gateway port.
  • The first save on a computer downloads the embedding model (Qdrant/bge-small-en-v1.5-onnx-Q) from huggingface.co and its CDN hosts. After that, embeddings are computed on your computer, and later saves and queries contact only your store gateway.
  • The embedding runtime (ONNX Runtime) sends a usage event to mobile.events.data.microsoft.com on that first run and writes a device id under ~/.cache/Microsoft/DeveloperTools/.onnxruntime/.
  • The Claude Code and Codex plugins ask the marketplace they were installed from for a newer plugin at most once every 24 hours: loomcloud.ai for a plugin installed from the hosted marketplace (including on a private install that fell back to it), your own server for a plugin installed from your private server's /loom-plugins.git. No memory data is sent. Set LOOM_PLUGIN_SKIP_REMOTE=1 to disable the check.
  • loom setup contacts only the server it signs in to (--base, or the single origin recorded in stores.toml, or LOOM_WEB_BASE, or https://loomcloud.ai) and installs plugins from that same server. The loom command installer is fetched from loomcloud.ai (or from LOOM_CLI_BOOTSTRAP_URL), because a private server does not serve it.

Who can read your data#

The connection between your computer and the server is encrypted and the server authenticates itself to your client. A store's endpoint and server public key are bearer connection material: anyone holding a valid store key and endpoint can connect, which is why the file must stay private.

Your browser session#

Report a security issue#

Do not open a public issue for a vulnerability or credential exposure. Email info@loomcloud.ai with a short description and a reproduction that contains no live keys or personal data.