安全與合規Security & Compliance
加密Encryption
所有連線採 HTTPS/TLS 傳輸加密,資料於儲存時加密。金鑰與密碼以 Secrets 管理,不寫入程式碼或版本庫。All traffic uses HTTPS/TLS; data is encrypted at rest. Keys and secrets are managed in a secrets store, never in code or the repo.
基礎設施Infrastructure
運行於 Cloudflare 全球邊緣網路,內建 DDoS 防護與 WAF。AI 推論在邊緣執行,降低資料傳輸面。Runs on Cloudflare's global edge with built-in DDoS protection and WAF. AI inference runs at the edge, minimizing data movement.
權限控管Access control
多人團隊採角色權限;客戶資料以租戶隔離。可設定哪些情境一律需真人確認後才送出。Role-based access for teams; customer data is tenant-isolated. You can require human approval before certain replies go out.
用量上限與防濫用Usage caps & abuse control
每日與單一來源的 AI 用量上限可調,超量自動降級回覆,避免成本失控與濫用攻擊。Per-day and per-source AI caps are configurable; over the cap the system gracefully degrades — preventing runaway cost and abuse.
AI 治理AI governance
AI 以您的知識庫為依據作答、標示信心度、低信心轉真人;您與客戶的資料不用於訓練第三方模型。AI answers from your knowledge base, shows confidence, and escalates low-confidence cases; your and customers' data is not used to train third-party models.
資料可攜與刪除Data portability & deletion
您可隨時匯出對話與名單,或要求刪除帳戶與相關個資;不把您鎖在平台裡。Export conversations and contacts anytime, or request account/data deletion. We don't lock you in.
遵循台灣《個人資料保護法》Aligned with Taiwan's PDPA
我們依《個資法》的蒐集、處理、利用原則設計流程:明確告知目的、最小化蒐集、確保當事人權利(查詢、更正、刪除、停止利用)。對您客戶的資料,您為控管者、我們為受託處理者,僅依您的指示處理。Our processes follow the PDPA principles of collection, processing and use: clear purpose notice, data minimization, and protecting data-subject rights (access, correction, deletion, opt-out). For your customers' data you are the controller and we are your processor, acting only on your instructions.
共同責任Shared responsibility
| 我們負責We handle | 您負責You handle |
|---|---|
| 平台與基礎設施安全、加密、用量上限、AI 不外訓。Platform & infra security, encryption, usage caps, no external AI training. | 帳號與金鑰保管、對客戶取得告知同意、發送內容合法合規。Account/key safekeeping, customer notice & consent, lawful outbound content. |
回報安全問題Report a security issue
若您發現潛在漏洞或安全疑慮,請來信 security@luvai.net。我們感謝負責任的揭露,並會儘速處理。Found a potential vulnerability or concern? Email security@luvai.net. We appreciate responsible disclosure and act quickly.
隱私權政策Privacy Policy · 服務條款Terms of Service · 回首頁Home
*本頁說明我們目前實際採行的安全做法與方向,部分項目仍在持續強化中。正式認證(如 ISO 27001、SOC 2)尚在規劃、目前尚未取得,我們不會宣稱已具備;有合規需求歡迎來信確認最新狀態。*This page describes the security practices and direction we currently follow; some items are still being hardened. Formal certifications (e.g. ISO 27001, SOC 2) are planned and not yet obtained — we don't claim otherwise. Email us for current compliance status.