Do not commit API keys, bearer tokens, customer payloads, real prompts/responses, reviewer credentials, signing keys, or production evidence bundles.
The integration defaults to capture_content=False. Haystack content tracing is also disabled by default; keep it disabled unless your deployment explicitly permits content export.
Report suspected vulnerabilities privately through the security contact/channel published by LoopGrid. Do not post undisclosed vulnerabilities or credentials in public issues.