Security at Qwen-AI.chat

Last reviewed: August 4, 2026.

This page explains security boundaries that users can act on and the process for reporting a suspected vulnerability. It does not claim a certification, penetration-test result, audit, or contractual security guarantee.

Publicly verifiable protections

The public site is served over HTTPS and uses Cloudflare for content delivery and security at the network edge. At the review cutoff, public responses included HTTP Strict Transport Security, same-origin framing protection, a strict-origin-when-cross-origin referrer policy, and a restrictive permissions policy. These headers and provider configurations can change and do not remove application-level risk.

A public response cannot prove every internal control. This page therefore does not promise a specific WAF rule set, bot-management product, staff-access model, audit trail, patch interval, monitoring coverage, or incident-response service level unless that claim can be documented.

Chat and data boundaries

  • No chat account: the public chat does not require a site account, password, or payment card.
  • External inference: at the August 4, 2026 cutoff, prompts and supported image inputs were sent to Fireworks AI using accounts/fireworks/models/qwen3p7-plus. Provider-side processing follows the selected provider route and account configuration.
  • Site retention: the current chat plugin is configured to retain conversation, message, and usage records for 30 days and run daily cleanup. This does not establish the provider’s separate retention period.
  • Rate limiting: the chat data uses a salted one-way network identifier rather than storing a readable IP address in the chat records. Hosting, Cloudflare, and security logs are separate systems.
  • Images: optional images can contain highly sensitive information. Do not upload faces, identity documents, medical material, confidential screenshots, credentials, or regulated data.

The Privacy Policy is the controlling public explanation of current data categories, purposes, retention, cookies, advertising, service providers, and privacy requests. Recheck it whenever the chat provider, model ID, upload behavior, or retention configuration changes.

How users can reduce risk

  • Do not place API keys, passwords, private source code, customer records, legal documents, health data, or confidential business information in prompts, images, comments, or contact messages.
  • Treat model output as untrusted. Verify facts and validate generated code, links, files, commands, and structured data before use.
  • Use official enterprise services and contractual controls when your workload requires data residency, regulated processing, guaranteed deletion, access controls, or support commitments.
  • Report unexpected behavior without probing other accounts, bypassing controls, causing disruption, or downloading data that is not yours.

Responsible vulnerability disclosure

Email [email protected] with the affected URL or component, a concise description, reproducible steps, expected and observed behavior, and the minimum evidence needed to understand the issue. Remove credentials, personal data, and third-party secrets from screenshots or logs.

Do not perform denial-of-service testing, social engineering, phishing, physical attacks, automated destructive scanning, persistence, data exfiltration, or testing against third-party providers without their authorization. Stop if you encounter personal or confidential data and report the exposure without retaining or sharing it.

We do not currently promise a bug bounty, payment, legal safe harbor, or a fixed response deadline. Reports will be reviewed as capacity allows, and legally required notifications will be handled where applicable.

Service and provider boundaries

Qwen-AI.chat is independent. Security or account issues involving official Alibaba Cloud, QwenCloud, Qwen Chat, Fireworks AI, Cloudflare, Google, or another external service must also follow that provider’s disclosure and support process. See the Terms of Service for acceptable use.