Security
Last updated: 2026-05-27
Official upstream channels
ModelAPI 通过 AWS Bedrock、Google Cloud API、DeepSeek 等厂商授权的企业接口调用模型,不使用逆向破解或盗号池。Claude 类模型在平台账户下默认经 Bedrock 路由。
BYOK(自带 Key)用户可选择直连 Anthropic 等厂商;密钥仅用于完成您的模型调用与编排,我们不会在未经同意的情况下将 BYOK 密钥用于其他客户。
Transport & storage
- TLS 1.2+ for all public endpoints (api.aimodelapi.ai).
- API keys stored as hashes; full key shown once at creation.
- Database and Redis on isolated production network; secrets via environment variables.
- Stripe PCI DSS for card payments — we do not store full card numbers.
Abuse prevention
- Per-key rate limits and spend caps.
- Concurrency limits to protect shared infrastructure.
- Account suspension for violations of Compliance Policy.
Your role
请勿在客户端、Git 或公开渠道泄露 API Key。敏感数据请最小化上传。合规与地域限制见 合规政策。
Report
漏洞或安全事件: security@aimodelapi.ai