Scope
This security policy applies to the AI assistant, documentation Q&A, knowledge retrieval, MCP search service, and related access protection and abuse-prevention features on Taixin websites.
This page focuses on AI assistant protection. For personal information processing, website terms, or other legal matters, please also refer to the privacy policy, terms of use, and other official notices published on the website.
Protection Objectives
Taixin security controls are designed to keep the public documentation assistant available, reliable, and controlled. We focus on reducing the following risks:
- Automated scripts, bulk requests, or abnormal traffic that may disrupt the service.
- Repeated questions, malicious cost consumption, prompt injection, or unauthorized retrieval attempts.
- Unexpected use of MCP, document retrieval, or Q&A interfaces that affects normal visitors.
- AI-generated answers being mistaken for formal commitments about specifications, certifications, pricing, stock, lead times, or replacement choices.
Access Identification And Session Protection
To distinguish normal access from abnormal behavior, we may use anonymous session identifiers, request source, request frequency, source page, and basic browser information for security decisions. Anonymous session identifiers are used for rate limits and risk control, not for public display or customer identity authentication.
When a user opens the AI assistant, submits a question, or calls the MCP search service, the system may record the page path, language, request time, anonymous session identifier, and result status to decide whether to allow, rate-limit, or challenge the request.
Rate Limits And Usage Budgets
The AI assistant applies multiple layers of rate limits configured in the admin console, including per-minute limits, per-session hourly limits, per-IP daily limits, and repeated-question thresholds. When a limit is reached, the system may temporarily reject requests and ask the user to try again later.
Rate limits may be adjusted based on service capacity, model cost, business traffic peaks, and abnormal traffic patterns. For normal users, rate limits help keep the service stable; for abnormal access, they reduce abuse and resource consumption.
Repeated Question And Abnormal Behavior Detection
The system may detect repeated submission of the same or highly similar questions within a short period. If an anonymous session repeatedly triggers the threshold, the assistant may pause responses to avoid unnecessary consumption.
The system may also identify abnormal patterns such as extremely high frequency, obvious non-browser behavior, direct API calls that bypass the website UI, unusually long input, attempts to probe system prompts, or content that tries to bypass safety rules. These cases may be rejected, slowed down, downgraded, or logged as security events.
Captcha And Security Challenges
When access risk is high, traffic is abnormal, or verification mode is enabled in the admin console, Taixin may use captcha, human verification, or similar security challenge mechanisms. These checks are used to confirm authentic access behavior and protect AI services, public documentation resources, and model budgets.
Verification is performed on the server side. High-risk requests continue to Q&A or retrieval only after verification succeeds. We choose suitable verification methods based on risk level and aim to minimize the information processed during verification.
MCP Service Protection
The Taixin documentation MCP service allows compatible developer tools to search public website sources. By default, MCP returns only public retrieval results and does not provide admin capabilities, keys, internal system information, or unpublished materials.
MCP calls are protected by the same Taixin security strategy, including request frequency limits, abnormal behavior detection, source tracking, and result-scope controls. If abnormal calls are detected, the system may limit MCP requests or temporarily disable MCP service.
Knowledge Base And Model Boundaries
The AI assistant retrieves from public website product information, solution pages, downloads, technical documentation, and support pages. Retrieved sources are used as answer context, but generated answers may still be incomplete, misread, or inaccurate.
The AI assistant is not designed to be the sole basis for contracts, quotations, certification commitments, stock commitments, delivery commitments, or replacement decisions. Critical specifications, certifications, pricing, stock, lead times, purchasing, samples, compatibility, and mass-production decisions should be verified through official documents, contract documents, or written confirmation from the Taixin team.
Input Content Management
Please do not submit passwords, keys, sensitive personal information, unpublished project materials, information covered by confidentiality obligations, or other content that should not be processed publicly. For project background, business requirements, or technical details, please use the website contact form or official channels agreed with the Taixin team.
The system may truncate, reject, or downgrade overly long input, abnormal formats, suspected attack payloads, or clearly irrelevant content to protect service stability and answer quality.
Logs And Security Review
To keep the service reliable and troubleshoot issues, we may record necessary operational logs, including request time, request path, anonymous session identifier, IP rate-limit key, language, matched sources, error status, rate-limit status, and feedback results.
Logs are mainly used for security review, troubleshooting, capacity planning, knowledge-base quality improvement, and abuse prevention. We aim to minimize log scope and control access permissions and retention periods according to business needs and compliance requirements.
Feedback And Manual Review
Users can report inaccurate answers, missing sources, or security-related issues through assistant feedback buttons, the website contact form, or other channels provided by Taixin. For important issues, the Taixin team may correct content based on public sources, internal workflows, and manual review.
Policy Updates
Taixin may update this security policy according to product changes, model capabilities, attack trends, service capacity, and compliance requirements. Updates will be published on this page, and the displayed update time will apply.
