Trust center

Security starts with narrow keys and visible limits

The service can enforce gateway controls, but customers still need server-side key storage, user authorization and safe handling of model output.

Planned recharge methods: Alipay and USDT. Collection is not enabled yet.

Customer controls

  • Store keys only on trusted servers.
  • Use separate projects and keys for production and testing.
  • Restrict models, IPs, rates, concurrency and budgets.
  • Rotate a key after suspected exposure.
  • Validate model output before side effects.

Platform controls

  • Upstream credentials remain server-side.
  • Usage and balance changes are auditable.
  • Administrative access should be role-limited and logged.
  • Public status and support paths should document incidents without exposing secrets.

Report a vulnerability

Use the published contact channel and include reproducible evidence. Do not access other users' data, interrupt production traffic or disclose a vulnerability before a reasonable remediation period.

Related resources