Security

How we protect your data. Encryption, privacy, and security practices.

Fanafangoana mandritra ny fivezivezena

Voafidin'ny HTTPS (TLS 1.2+) ny fifamoivoizana rehetra eo amin'ny mpitety anao sy ny Free.ai. Voafidin'ny end-to-end ihany koa ny fangatahana API mankany amin'ny mpizara GPU. Ampiharinay ny HSTS mba hisorohana ny fanafihana amin'ny alalan'ny fanavaozana.

Tsy ampiasaina amin'ny fanazarantena ny angon-drakitrao

Tsy mampiasa ny angon-drakitrao, ny vokatrao, na ny rakitrao nalefa izahay mba hanampiana modely AI - na oviana na oviana - raha tsy hoe mifidy izany ianao. Anao ny angon-drakitrao.

PCI-Compliant Payments

Ny Stripe, izay manana ny fankatoavana PCI Level 1, no misahana ny fandoavam-bola rehetra. Tsy mitahiry ny laharan'ny karatrao, ny CVV, na ny antsipirian'ny karatrao manontolo ao amin'ny lohamilinay izahay.

Open-source & Auditable Models

Ny modely AI izay iarahantsika mikarakara dia loharano misokatra rehetra eo ambanin'ny fahazoan-dàlana (Apache 2.0 sy MIT). Azo jerena avokoa ny lanjany, ny rafitra ary ny fomba fanao amin'ny fanazarantena ary azo jerena tsy miankina amin'ny olona rehetra.

Tsy misy data mivarotra

Tsy mivarotra, manome an-trano, na mizara ny angon-drakitrao manokana amin'ny antoko fahatelo izahay ho an'ny dokambarotra na tanjon'ny varotra.

Fiarovana ny fotodrafitrasa

Mipetraka amin'ny VPS sy ny fotodrafitrasa GPU an'aona ny lohamilinay, miaraka amin'ny famaha SSH ihany no fahazoana miditra, fanavaozana ny fiarovana mandeha ho azy, ary ny fitsipiky ny firewall izay manakana ny fifamoivoizana amin'ireo ports ilaina ihany.

Misy olana momba ny fiarovana ve ianao? Mifandraisa aminay.

FAQ

Yes. All traffic between your browser and Free.ai is encrypted with HTTPS using TLS 1.2+. API requests to our GPU inference server are also encrypted end-to-end. We enforce HSTS to prevent downgrade attacks.

No. We never use your inputs, outputs, or uploaded files to train AI models unless you explicitly opt in. This applies to all users -- free, paid, and enterprise.

All payment processing is handled by Stripe, a PCI Level 1 certified processor. We never store your credit card number, CVV, or full card details on our servers. Stripe handles all sensitive payment data.

Yes. All self-hosted models are open-source under permissive licenses (Apache 2.0, MIT). The model weights, architectures, and training methodologies are publicly available on HuggingFace and GitHub for anyone to audit.

No. We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. This is a firm policy with no exceptions.

Our servers use SSH key-only access (no password authentication), automatic security updates, firewall rules restricting traffic to necessary ports, and encrypted database backups. We follow security best practices for all infrastructure.

Uploaded files (images, audio, documents) are processed for the requested AI task and are not retained permanently. They are not used for training, shared with other users, or sold to third parties.

We follow GDPR principles including data minimization, purpose limitation, and the right to deletion. Enterprise customers can choose EU data residency through private cloud deployment. Contact us for a Data Processing Agreement (DPA).

Eny. Fafao ny kaontinao rehefa tianao. Hanafoana ny angon-drakitrao manokana, ny diary, ny famoronana ary ny famaha API izany. Tsy azo lavina ny fafàna ka atao avy hatrany.

We monitor for vulnerabilities continuously and apply security patches promptly. If you discover a security issue, please report it to us through the contact form. We take all reports seriously and respond quickly.

Not directly, not yet — we would rather say so than imply otherwise. If you want a second factor on your Free.ai account today, sign in with Google instead of a password: your Google account's 2FA then protects your Free.ai sign-in too, including any hardware key or authenticator app you already use there. Password accounts are protected by hashed credentials and rate-limited sign-in attempts, but no second factor. Native 2FA and enterprise SSO enforcement are not currently available.

API keys are hashed before storage and transmitted only over HTTPS. You can revoke and regenerate keys at any time from the developer settings. We recommend rotating keys regularly and never sharing them publicly.

Tianao ve ny Free.ai? Lazao amin'ny namanao!

Manome isa ity pejy ity