Security

Security

What SLM protects, what it does not do yet, and what you need to add before sharing it.

What SLM does by design

  • It runs where you host it. Your documents and the model stay on that machine unless you switch on a cloud model or a cloud judge.
  • Each answer is built from the sections it retrieved from your documents, and sentences are checked against those sections.
  • Trained adapters can reproduce parts of the text they learned from, so we treat them as confidential.
  • The web app listens on your own machine by default.

What it does not do yet

  • No user accounts. Anyone who can reach the web app can use every source. Put it behind your login, VPN, or single sign-on.
  • No per-document permissions. Access is all or nothing for each source.
  • No built-in audit trail of who asked what.
  • No rate limits in the app itself. Limits, where they exist, are set on the web server in front of it.

The public demo

The live demo at slm.qaso.ai exposes one API route: asking a question of one of the three sample sources. Every other path under /api/ is closed at the web server. Questions to the demo are limited to six per minute per visitor, with short bursts allowed. The demo runs on a server we operate, and questions sent to it are handled there. See the privacy page.

Before you share an install

  • Put it behind a login or a VPN. Do not expose the web app port to the internet.
  • Keep it bound to 127.0.0.1, or restrict it with a firewall allow-list.
  • Use HTTPS (for example, with nginx and Let's Encrypt) for any address other people can reach.
  • Keep trained adapters and source texts in access-controlled folders.
  • Keep Python packages and the model backend up to date.

Reporting a problem

To report a security problem, email sohil@qaso.ai. Please describe the problem and how to reproduce it. Do not test against systems you do not own.