๐ Security & Privacy
Data protection ยท Access control ยท Compliance
Privacy Score
98%
Failed Auth (24h)
7
Active Tokens
247
Last Audit
2d ago
๐ก๏ธ Data Privacy Compliance
โ
In-Transit Processing
All customer data processed in memory only โ never written to disk on Central
โ
Zero Data Retention
KB chunks, conversations, and training data deleted from RAM after each request
โ
Customer Data Isolation
Customer media stored in R2 with per-customer key prefixes โ cross-tenant access blocked
โ
Job Persona Anonymization
Persona patterns contain zero customer-identifying information โ verified by automated scan
โ
WebSocket Encryption
All visitor โ Central communication uses WSS (TLS 1.3) โ no plaintext ever
๐ Access Control
๐
API Key Validation
Every request validates customer API key + plan tier โ expired keys rejected
๐
Customer Suspend
Instant customer suspension capability โ blocks all API access
๐ก๏ธ
DashScope API Key Rotation
Qwen API keys rotated every 30 days โ next rotation in 12 days
โ ๏ธ
2FA for Admin Dashboard
Two-factor authentication for this dashboard โ recommended but not yet enabled
๐
Audit Trail
All admin actions logged with IP, timestamp, and action details