Security
How boxai is built to limit harm. We describe what is in place today, and what is not.
In place today
- Everything you build runs in a locked sandbox with no network access. Your code cannot call other sites or read the workspace, your access code or other users' pages.
- Published pages run in a separate sandbox that cannot send data anywhere, so a page cannot collect visitors' passwords or details.
- Every AI request needs an access code. Codes are stored only as hashes, can be switched off instantly, and have per-minute and daily limits.
- Strict content security policy and standard security headers on every page. No third-party scripts, ads or trackers.
- Requests are size-limited and validated. Model names and settings are fixed on the server.
- Message and file contents are not logged.
- Published pages show a report link, and anyone can report a page by name. We can remove any page or pause the service from the command line.
- Published pages expire automatically.
Not in place yet
- UAE-only data hosting. Today the service runs on Cloudflare's global network.
- Individual user accounts and sign-in with Google. Access is by code during early access.
- An independent penetration test or formal certification (such as ISO 27001 or SOC 2).
Reporting a problem
If you find a vulnerability, please tell us through the report form and start the message with “SECURITY”. Please give us reasonable time to fix it before sharing details publicly.
الأمان
كيف صُمّمت boxai للحدّ من الضرر. نذكر ما هو قائم اليوم وما ليس قائمًا بعد.
قائم اليوم
- كل ما تبنيه يعمل في بيئة معزولة بلا اتصال بالشبكة. لا يستطيع كودك استدعاء مواقع أخرى ولا قراءة مساحة العمل أو رمز دخولك أو صفحات مستخدمين آخرين.
- تعمل الصفحات المنشورة في بيئة معزولة منفصلة لا تستطيع إرسال بيانات إلى أي جهة، فلا يمكن لصفحة أن تجمع كلمات مرور الزوار أو بياناتهم.
- يتطلب كل طلب ذكاء اصطناعي رمز دخول. تُحفظ الرموز كبصمات مشفّرة فقط، ويمكن إيقافها فورًا، ولها حدود في الدقيقة وفي اليوم.
- سياسة أمان محتوى صارمة ورؤوس أمان قياسية في كل صفحة. لا سكربتات طرف ثالث ولا إعلانات ولا متتبعات.
- الطلبات محدودة الحجم ويتم التحقق منها. أسماء النماذج وإعداداتها ثابتة على الخادم.
- لا يتم تسجيل محتوى الرسائل والملفات.
- تعرض الصفحات المنشورة رابط إبلاغ، ويمكن لأي شخص الإبلاغ عن صفحة باسمها. يمكننا إزالة أي صفحة أو إيقاف الخدمة من سطر الأوامر.
- تنتهي الصفحات المنشورة تلقائيًا.
غير قائم بعد
- استضافة البيانات داخل الإمارات فقط. تعمل الخدمة اليوم على شبكة Cloudflare العالمية.
- حسابات المستخدمين والدخول عبر Google. الدخول برمز خلال مرحلة الوصول المبكر.
- اختبار اختراق مستقل أو شهادة رسمية (مثل ISO 27001 أو SOC 2).
الإبلاغ عن مشكلة
إذا اكتشفت ثغرة فأبلغنا عبر نموذج البلاغ وابدأ الرسالة بكلمة SECURITY. نرجو منحنا وقتًا معقولًا للإصلاح قبل نشر التفاصيل علنًا.