Security and data.
Understand access, credentials, and data handling before connecting your work to Ablix.
Access belongs to an account
Saved conversations are checked against the signed-in account. Organization operations check membership and role on the server. An identifier in a URL is not permission to read or change another account’s data.
Credentials stay under your control
Use a separate API key for each integration and keep it on the server. Revoke a key if it is exposed or no longer needed. Never include an API key in a support request, shared screenshot, browser bundle, or public repository.
Passwords are handled by the authentication system rather than stored as plain text. Sign out on shared devices and use a trusted sign-in method.
Requests have defined boundaries
The server validates request input and verifies access before handling protected operations. Public model identifiers are resolved on the server. Private credentials and routing configuration are not part of the model catalogue.
These application controls do not establish an independent security certification, contractual uptime commitment, or specific infrastructure configuration. Ask for evidence of any control required by your organization.
Retention is part of the decision
Saved conversations are retained to provide chat history. Data handling describes what the product stores and which processing details need confirmation. Do not assume that every model supports zero retention, a particular processing region, or the same training restrictions.
Report a security concern
Email support@ablix.ai with the subject “Security report”. Include the affected feature, the time observed, and safe steps to reproduce. Redact credentials and personal content. If you discover someone else’s data, stop accessing it and report the minimum information needed to identify the issue.