Platform Security & Guidelines

Security Guidelines & Limitations

Understanding our open-source AI architecture, prompt data limitations, and developer security responsibilities.

Critical Notice: No Security Guarantee for Prompts & Payloads

Due to the inherent technical and security limitations of AI model inference and system logging for usage accounting, techLauncher.in does NOT guarantee confidentiality, data protection, or security for prompt text, input context, or generated model outputs.

We strongly advise and require that developers NEVER pass sensitive data, private credentials, API keys, passwords, database strings, or confidential proprietary secrets into the API.

1. Open Source Model Execution (No Third-Party Contracts)

techLauncher.in operates a direct gateway to open source AI foundation models. When you send an API request:

  • Requests are passed directly to open-source models executed within our compute environment.
  • We do not resell closed proprietary models and do not rely on third-party commercial vendor contracts.
  • Prompts and completions are stored in system logs strictly to calculate INR wallet deductions and maintain your dashboard usage history.

2. Developer Responsibility & Prompt Sanitization

Developers bear sole responsibility for all data transmitted through their API keys. Before sending requests to techLauncher.in, you must ensure:

  • No Authentication Secrets: Never include database passwords, bearer tokens, private RSA/SSH keys, or environment secrets in prompts.
  • No Regulated PII: Do not submit unmasked personal data, government IDs, health records, or credit card numbers.
  • Sanitized Payloads: Pre-filter and sanitize user-submitted inputs in your own applications before dispatching inference calls.

3. API Key Management

We implement industry-standard cryptographic practices for developer authorization:

  • One-Time Key Generation: Secret API keys (`tl_live_...`) are displayed only once upon generation and cannot be retrieved in plaintext later.
  • Key Hashing: We persist only secure SHA-256 hashes and key prefixes in our database for authorization verification.
  • Instant Revocation: If you suspect an API key has been exposed or compromised, you can revoke it immediately from the dashboard to halt all future billable requests.

4. Transport & Network Protections

Standard HTTPS / TLS encryption is enforced for data in transit between client applications and our edge API servers. Automated rate limiters help protect accounts against runaway request loops and denial-of-service attempts.

5. Security Inquiries & Vulnerability Reporting

If you discover a vulnerability or have a security inquiry regarding our gateway, please contact our support team at support@techlauncher.in.