Security at Qwen-AI.chat

Last reviewed: August 23, 2026.

This page explains security boundaries that users can act on and the process for reporting a suspected vulnerability. It does not claim a certification, penetration-test result, audit, or contractual security guarantee.

Publicly verifiable delivery facts

As verified on August 23, 2026, the public site is available over HTTPS, is delivered through Cloudflare, and uses LiteSpeed Cache at the origin. Plain HTTP currently returns site content instead of a verified automatic redirect to HTTPS. The reviewed response did not establish HTTP Strict Transport Security or a defined set of browser security headers, so this page does not claim those controls are enabled. Delivery and provider configurations can change and do not remove application-level risk.

A public response cannot prove every internal control. This page therefore does not promise a specific WAF rule set, bot-management product, staff-access model, audit trail, patch interval, monitoring coverage, or incident-response service level unless that claim can be documented.

Chat and data boundaries

  • No chat account: the public chat does not require a site account, password, or payment card.
  • External inference: as verified on August 23, 2026, prompts and supported image inputs are sent to Fireworks AI using accounts/fireworks/models/qwen3p7-plus. Provider-side processing follows the selected provider route and account configuration.
  • Site retention: as verified on August 23, 2026, the chat plugin is configured to retain conversation, message, and usage records for 30 days and run daily cleanup. This does not establish the provider’s separate retention period.
  • Rate limiting: the chat data uses a salted one-way network identifier rather than storing a readable IP address in the chat records. Hosting, Cloudflare, and security logs are separate systems.
  • Images: optional images can contain highly sensitive information. Do not upload faces, identity documents, medical material, confidential screenshots, credentials, or regulated data.

The Privacy Policy is the controlling public explanation of current data categories, purposes, retention, cookies, advertising, service providers, and privacy requests. Recheck it whenever the chat provider, model ID, upload behavior, or retention configuration changes.

How users can reduce risk

  • Do not place API keys, passwords, private source code, customer records, legal documents, health data, or confidential business information in prompts, images, comments, or contact messages.
  • Treat model output as untrusted. Verify facts and validate generated code, links, files, commands, and structured data before use.
  • Use official enterprise services and contractual controls when your workload requires data residency, regulated processing, guaranteed deletion, access controls, or support commitments.
  • Report unexpected behavior without probing other accounts, bypassing controls, causing disruption, or downloading data that is not yours.

Responsible vulnerability disclosure

Email info@qwen-ai.chat with the affected URL or component, a concise description, reproducible steps, expected and observed behavior, and the minimum evidence needed to understand the issue. Remove credentials, personal data, and third-party secrets from screenshots or logs.

Do not perform denial-of-service testing, social engineering, phishing, physical attacks, automated destructive scanning, persistence, data exfiltration, or testing against third-party providers without their authorization. Stop if you encounter personal or confidential data and report the exposure without retaining or sharing it.

We do not currently promise a bug bounty, payment, legal safe harbor, or a fixed response deadline. Reports will be reviewed as capacity allows, and legally required notifications will be handled where applicable.

Service and provider boundaries

Qwen-AI.chat is independent. Security or account issues involving official Alibaba Cloud, QwenCloud, Qwen Chat, Fireworks AI, Cloudflare, Google, or another external service must also follow that provider’s disclosure and support process. See the Terms of Service for acceptable use.