安全與合規Security & Compliance

🔒 傳輸與儲存加密Encrypted in transit & at rest 🇹🇼 遵循個資法 PDPAPDPA-aligned 🚫 不用於訓練第三方模型No third-party model training 📤 資料可匯出/刪除Exportable & deletable

加密Encryption

所有連線採 HTTPS/TLS 傳輸加密,資料於儲存時加密。金鑰與密碼以 Secrets 管理,不寫入程式碼或版本庫。All traffic uses HTTPS/TLS; data is encrypted at rest. Keys and secrets are managed in a secrets store, never in code or the repo.

基礎設施Infrastructure

運行於 Cloudflare 全球邊緣網路,內建 DDoS 防護與 WAF。AI 推論在邊緣執行,降低資料傳輸面。Runs on Cloudflare's global edge with built-in DDoS protection and WAF. AI inference runs at the edge, minimizing data movement.

權限控管Access control

多人團隊採角色權限;客戶資料以租戶隔離。可設定哪些情境一律需真人確認後才送出。Role-based access for teams; customer data is tenant-isolated. You can require human approval before certain replies go out.

用量上限與防濫用Usage caps & abuse control

每日與單一來源的 AI 用量上限可調,超量自動降級回覆,避免成本失控與濫用攻擊。Per-day and per-source AI caps are configurable; over the cap the system gracefully degrades — preventing runaway cost and abuse.

AI 治理AI governance

AI 以您的知識庫為依據作答、標示信心度、低信心轉真人;您與客戶的資料不用於訓練第三方模型。AI answers from your knowledge base, shows confidence, and escalates low-confidence cases; your and customers' data is not used to train third-party models.

資料可攜與刪除Data portability & deletion

您可隨時匯出對話與名單,或要求刪除帳戶與相關個資;不把您鎖在平台裡。Export conversations and contacts anytime, or request account/data deletion. We don't lock you in.

遵循台灣《個人資料保護法》Aligned with Taiwan's PDPA

我們依《個資法》的蒐集、處理、利用原則設計流程:明確告知目的、最小化蒐集、確保當事人權利(查詢、更正、刪除、停止利用)。對您客戶的資料,您為控管者、我們為受託處理者,僅依您的指示處理。Our processes follow the PDPA principles of collection, processing and use: clear purpose notice, data minimization, and protecting data-subject rights (access, correction, deletion, opt-out). For your customers' data you are the controller and we are your processor, acting only on your instructions.

共同責任Shared responsibility

回報安全問題Report a security issue

若您發現潛在漏洞或安全疑慮,請來信 security@luvai.net。我們感謝負責任的揭露,並會儘速處理。Found a potential vulnerability or concern? Email security@luvai.net. We appreciate responsible disclosure and act quickly.