Trust and security
This is the model Loaf is built towards: intent-derived controls that are enforced, not just documented, with evidence you can check rather than a claim you have to trust. Where we are still building towards it, we say so below rather than overstate where we are today.
Guardrails
Example: a support agent is scoped to read tickets and draft replies. Before it runs, that scope becomes policy: no ticket deletion, no access to billing records. The agent can't ask for more once it starts.
Egress policy
Example: a research agent is granted api.wikipedia.org and nothing else. A prompt injection that tries to route data to an unlisted domain is refused at the network boundary, not caught after the fact.
Sandbox constraints
Example: a coding agent gets a checkout of one repository and a resource ceiling for its run. A runaway loop or a compromised dependency stays inside that boundary instead of reaching the host.
Evidence they held
Example: after a run, you can pull the record of every control that was active and confirm none were bypassed. That's the difference between assuming a guardrail worked and proving it.
Where Loaf is today
Loaf is early. The site describes the target state of the controls above; the underlying enforcement is still being built out and has not yet been through independent audit. Treat what you see here as our design commitment and roadmap, not a certification. We will update this page as each control moves from design to enforced, and note any demo or preview limitations plainly rather than let the copy get ahead of the product.
No analytics or third-party scripts run on this site. Nothing here reaches beyond your own request for this page.