Privacy & Security Notice

How SecureAI Gateway protects tenant data, AI requests, model routing metadata, key-governance records and audit evidence for regional enterprise deployments.

Effective date: 29 July 2026

1. Scope

This notice applies to SecureAI Gateway websites, administration consoles, focused pilot environments, PoC deployments, support services and related business communications. SecureAI Systems Limited is registered in Hong Kong and serves enterprises across Hong Kong, Singapore and Southeast Asia.

2. Data We May Process

  • Account and contact data: username, name, title, department, email, phone, WhatsApp, tenant and role.
  • Tenant and operational data: organisation profile, industry categories, service status, Data Plane sites, model providers, provider connections, model routes, quota and cost settings.
  • AI governance data: risk decisions, matched rules, masked content, blocked reasons, Trace ID, model/provider selection and audit events.
  • Security and login data: login time, IP address, User Agent, identity source, enterprise authentication summaries, system operations and errors.
  • Key governance data: key ID, scope, owner, status and operation audit. Real key material should be held in a deployment secret manager or node environment variable; the database should hold only required metadata or encrypted credentials.

3. Purpose of Use

  • Provide enterprise AI access governance, governed model access and routing, governance policy, key governance, cost monitoring, audit reporting and support services.
  • Detect sensitive data, prompt injection, data exfiltration risk and tenant-policy violations before model invocation.
  • Support Tenant Admins in managing tenant configuration and Super Admins in reviewing cross-tenant health, warnings, history and platform security.
  • Troubleshoot issues, monitor security, support compliance review, plan capacity and retain records required by contract, audit or applicable law.

4. Control Plane and Data Plane Boundary

The Control Plane stores configuration, summaries, audit records and management data. It should not store enterprise identity passwords, LDAP bind passwords, raw SAML assertions, raw OAuth tokens or unencrypted provider credentials. The Data Plane may run in cloud, enterprise network or hybrid environments to perform request inspection, masking, blocking, policy decisions and provider connectivity.

5. Security Measures

  • Role separation: Super Admin manages platform review; Tenant Admin manages tenant configuration; Auditor reviews evidence; AI User uses approved AI services.
  • Tenant isolation: users, model routes, policies, reports and audit views are scoped by tenant.
  • Key governance: platform, tenant and node keys are tracked with metadata and audit events; key material should not be stored in plaintext.
  • Audit evidence: login, configuration changes, model requests, masking, blocking, License and key operations are retained for traceability.
  • Data minimisation: only information required for service delivery, risk control, support and compliance is retained.

6. Model Providers and Third Parties

When a tenant configures an external model provider, the Data Plane sends only the necessary governed content according to model routing and policy settings. Tenant Admins should choose provider, model, endpoint, region and terms according to enterprise policy and applicable regional requirements. We do not sell personal data.

7. Retention, Access and Correction

Records are retained according to service, contract, audit, security and legal needs. Tenant users should contact their Tenant Admin for tenant-scoped records. Platform or business-contact requests can be sent to [email protected].

8. Contact

SecureAI Systems Limited
Hong Kong registered | Serving Hong Kong, Singapore and Southeast Asia
Room 721A, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Hong Kong
Email: [email protected]
Tel: +852 6158 8111

隐私与安全声明

说明 SecureAI Gateway 如何为区域企业部署保护租户数据、AI 请求、模型路由元数据、密钥治理记录和审计证据。

生效日期:2026年7月29日

1. 适用范围

本声明适用于 SecureAI Gateway 官网、管理控制台、聚焦试点环境、PoC 部署、支持服务及相关商务沟通。安智雲科技有限公司(SecureAI Systems Limited)注册于香港,服务香港、新加坡及东南亚企业。

2. 我们可能处理的数据

  • 账户和联系数据:用户名、姓名、职务、部门、邮箱、电话、WhatsApp、租户和角色。
  • 租户和运营数据:机构资料、行业类别、服务状态、Data Plane 站点、模型供应商、供应商连接、模型路由、配额和成本设置。
  • AI 治理数据:风险决策、命中规则、已遮蔽内容、阻断原因、Trace ID、模型/供应商选择和审计事件。
  • 安全和登录数据:登录时间、IP 地址、User Agent、身份来源、企业认证摘要、系统操作和错误。
  • 密钥治理数据:密钥 ID、范围、所有人、状态和操作审计。真实密钥材料应保存在部署 Secret Manager 或节点环境变量中;数据库只应保存必要元数据或加密凭据。

3. 使用目的

  • 提供企业 AI 访问治理、受治理模型访问与路由、治理策略、密钥治理、成本监控、审计报告和支持服务。
  • 在模型调用前检查敏感数据、提示词注入、数据外泄风险和租户策略违规。
  • 支持租户管理员管理租户配置,并支持超级管理员复核跨租户健康状态、告警、历史记录和平台安全。
  • 排查问题、监控安全、支持合规评审、规划容量,并保留合同、审计或适用法律要求的记录。

4. Control Plane 与 Data Plane 边界

Control Plane 存储配置、摘要、审计记录和管理数据。它不应存储企业身份密码、LDAP 绑定密码、原始 SAML 断言、原始 OAuth Token 或未加密的供应商凭据。Data Plane 可运行在云端、企业网络或混合环境中,用于执行请求检查、遮蔽、阻断、策略决策和供应商连接。

5. 安全措施

  • 角色分离:超级管理员管理平台复核;租户管理员管理租户配置;审计员复核证据;AI 用户使用已批准 AI 服务。
  • 租户隔离:用户、模型路由、策略、报告和审计视图按租户范围隔离。
  • 密钥治理:平台、租户和节点密钥通过元数据和审计事件进行追踪;密钥材料不应以明文存储。
  • 审计证据:登录、配置变更、模型请求、遮蔽、阻断、License 和密钥操作会保留用于追溯。
  • 数据最小化:仅保留服务交付、风险控制、支持和合规所需的信息。

6. 模型供应商和第三方

当租户配置外部模型供应商时,Data Plane 会根据模型路由和策略设置,仅发送必要的受治理内容。租户管理员应根据企业策略和适用区域要求选择供应商、模型、端点、区域和条款。我们不出售个人数据。

7. 保留、访问和更正

记录会根据服务、合同、审计、安全和法律需要保留。租户用户如需处理租户范围内记录,应联系其租户管理员。平台或商务联系请求可发送至 [email protected]

8. 联系方式

安智雲科技有限公司(SecureAI Systems Limited)
香港注册 | 服务香港、新加坡及东南亚
香港尖沙咀梳士巴利道 3 号星光行 7 楼 721A 室
Email: [email protected]
Tel: +852 6158 8111

私隱與安全聲明

說明 SecureAI Gateway 如何為區域企業部署保護租戶數據、AI 請求、模型路由元數據、密鑰管治記錄和審計證據。

生效日期:2026年7月29日

1. 適用範圍

本聲明適用於 SecureAI Gateway 官網、管理控制台、聚焦試點環境、PoC 部署、支援服務及相關商務溝通。安智雲科技有限公司(SecureAI Systems Limited)註冊於香港,服務香港、新加坡及東南亞企業。

2. 我們可能處理的數據

  • 帳戶和聯絡數據:用戶名、姓名、職務、部門、電郵、電話、WhatsApp、租戶和角色。
  • 租戶和營運數據:機構資料、行業類別、服務狀態、Data Plane 站點、模型供應商、供應商連接、模型路由、配額和成本設定。
  • AI 管治數據:風險決策、命中規則、已遮蔽內容、阻斷原因、Trace ID、模型/供應商選擇和審計事件。
  • 安全和登入數據:登入時間、IP 地址、User Agent、身分來源、企業認證摘要、系統操作和錯誤。
  • 密鑰管治數據:密鑰 ID、範圍、擁有人、狀態和操作審計。真實密鑰材料應保存在部署 Secret Manager 或節點環境變數中;資料庫只應保存必要元數據或加密憑據。

3. 使用目的

  • 提供企業 AI 存取管治、受管治模型存取與路由、管治政策、密鑰管治、成本監控、審計報告和支援服務。
  • 在模型調用前檢查敏感數據、提示詞注入、數據外洩風險和租戶政策違規。
  • 支援租戶管理員管理租戶配置,並支援超級管理員覆核跨租戶健康狀態、警示、歷史記錄和平台安全。
  • 排查問題、監控安全、支援合規評審、規劃容量,並保留合約、審計或適用法律要求的記錄。

4. Control Plane 與 Data Plane 邊界

Control Plane 儲存配置、摘要、審計記錄和管理數據。它不應儲存企業身分密碼、LDAP 綁定密碼、原始 SAML 斷言、原始 OAuth Token 或未加密的供應商憑據。Data Plane 可運行於雲端、企業網絡或混合環境中,用於執行請求檢查、遮蔽、阻斷、政策決策和供應商連接。

5. 安全措施

  • 角色分離:超級管理員管理平台覆核;租戶管理員管理租戶配置;審計員覆核證據;AI 用戶使用已批准 AI 服務。
  • 租戶隔離:用戶、模型路由、政策、報告和審計視圖按租戶範圍隔離。
  • 密鑰管治:平台、租戶和節點密鑰透過元數據和審計事件進行追蹤;密鑰材料不應以明文儲存。
  • 審計證據:登入、配置變更、模型請求、遮蔽、阻斷、License 和密鑰操作會保留用於追溯。
  • 數據最小化:僅保留服務交付、風險控制、支援和合規所需的資訊。

6. 模型供應商和第三方

當租戶配置外部模型供應商時,Data Plane 會根據模型路由和政策設定,僅發送必要的受管治內容。租戶管理員應根據企業政策和適用區域要求選擇供應商、模型、端點、區域和條款。我們不出售個人數據。

7. 保留、存取和更正

記錄會根據服務、合約、審計、安全和法律需要保留。租戶用戶如需處理租戶範圍內記錄,應聯絡其租戶管理員。平台或商務聯絡請求可發送至 [email protected]

8. 聯絡方式

安智雲科技有限公司(SecureAI Systems Limited)
香港註冊 | 服務香港、新加坡及東南亞
香港尖沙咀梳士巴利道 3 號星光行 7 樓 721A 室
Email: [email protected]
Tel: +852 6158 8111