AIOffice AI Add-in

Security

This page describes the basic security practices for the public site, download channel, account system, and community content. It will be expanded when a corporate entity, payments, and third-party sign-in are introduced.

Accounts and identity

A community account has one server-side user ID. Phone, email, WeChat, QQ, and similar identities can be linked to it, keeping future plan entitlements and purchase records together.

Content and abuse prevention

Forum posts and replies have basic rate limits. Administrators may hide, close, or pin topics and replies. Public pages never expose admin tokens, payment keys, or server configuration.

Download security

Installers are published through the update manifest with verification details. For a public release, use HTTPS, a Cloudflare proxy, backup domains, and verification values together.

Data and backups

The server stores the account, community, feedback, and purchase records needed to operate the service, with database snapshots kept through server-side backups. Redact feedback containing user files or business information first.