How Latorium protects your project

Latorium limits what automated work can touch, strips dangerous process settings, and keeps an audit trail you can read.

The safeguards built into each change

01

Protected paths

Traversal attempts and edits outside the allowed workspace are rejected before a command runs.

02

Safer processes

Interpreter preload variables are removed and operations are checked before local execution.

03

Secret redaction

Credential-shaped output is hidden before it becomes saved context or a shareable report.

04

Partial rollback

A failed change can restore its affected dependency group without throwing away unrelated passing work.

05

Package scanning

The release gate scans the exact VSIX contents for secrets and unexpected bundled files.

YOU

Still in control

Drafts are not silently applied, saved memory is editable, and the workspace audit log remains inspectable.

What each system can see

Latorium retrieval and memory
workspace files, stored locally
Local Coder drafting
the local excerpts it receives
Claude Code or Codex
the compact packet sent to that provider
Latorium licensing service
account and plan metadata only; there is no code-upload endpoint

Using a cloud agent sends selected context to its provider. Latorium Local Coder sends nothing off this machine.

Failed work can be restored

A corrupt index is quarantined and rebuilt. A schema from a newer Latorium version is left intact. Stale retrievals are invalidated after file changes, and repair loops stop when further attempts stop improving the result.