Security
The strongest security property of this product is that we do not hold your keys, your prompts, or your output. There is nothing there to breach.
Last updated 2026-07-23
We hold no API keys
Loadout never asks for, stores, or proxies an API key. Everything you buy runs inside the AI account you already have. If this site were compromised tomorrow, an attacker would find no model credentials belonging to you, because none were ever collected.
We hold no prompts or output
The files you download are static. They do not call home, they contain no telemetry, and they report nothing back to us. We cannot see what you ran, what you fed it, or what it produced.
You can verify this yourself — the files are plain text and you can read every line before you use them.
What we do hold, and how
- Your email address and order record, in a database that is not publicly reachable.
- Password hashes, if you set a password — hashed, never reversible, never stored as text.
- Download tokens that are random, single-purpose, expiring, and capped in use count.
The whole site is served over HTTPS. Payment card details are never handled by us — when a card gateway is live, those go directly to the processor and never reach our servers.
Reporting a problem
If you find a vulnerability, please tell us before telling anyone else, via the contact page. We will acknowledge you, fix it, and credit you if you want the credit.
Questions about this page? Get in touch.