Security

This page explains the security practices and vulnerability-reporting process for Kimi-AI.free. It does not describe or make commitments for Kimi, Moonshot AI or another external service.

Our Security Approach

We use reasonable measures appropriate to an independent WordPress information website. These may include:

  • HTTPS encryption in transit.
  • Hosting, CDN and firewall controls.
  • Limited administrative access and strong account credentials.
  • WordPress, theme and plugin updates.
  • Malware, availability and suspicious-traffic monitoring.
  • Backups and restoration procedures.
  • Spam and abuse protection for public forms.
  • Review of third-party scripts and integrations.

No system is completely secure. We do not claim “100% security,” bank-level protection, certification or a formal bug-bounty program unless that statement is separately documented and current.

Protecting Yourself

  • Kimi-AI.free never needs your Kimi password, verification code or session cookie.
  • Do not enter an API key into an article, contact form or independent demo.
  • Use official Kimi links for login, signup, downloads and payment.
  • Review the domain before entering credentials.
  • Do not send confidential source code or personal files to our contact form.

Report a Vulnerability

Email [email protected] with:

  • Affected Kimi-AI.free URL or component.
  • Clear reproduction steps.
  • Expected and actual behavior.
  • Potential impact.
  • Minimal safe evidence.
  • Your preferred contact information.

Do not include passwords, unrelated personal data, destructive payloads or data obtained from another user.

Good-Faith Testing Rules

  • Test only systems owned or expressly controlled by Kimi-AI.free.
  • Do not test Kimi, Moonshot AI, hosting providers or third-party services through this policy.
  • Avoid denial of service, automated high-volume scanning and resource exhaustion.
  • Do not access, alter, retain or disclose another person’s data.
  • Stop when sensitive information or unauthorized access is encountered.
  • Do not use social engineering, physical attacks or credential theft.
  • Allow reasonable time for investigation before public disclosure.

What Is Outside Scope?

  • Kimi.com, Moonshot.ai, Kimi Open Platform, Kimi Code and official apps.
  • Third-party ad, analytics, CDN, hosting, form or consent-provider infrastructure.
  • Clickjacking without a meaningful impact.
  • Missing security headers without an exploitable consequence.
  • Rate limits or spam concerns that do not expose data or create material impact.
  • Public information and already known software-version details.

Our Response

We aim to acknowledge credible reports, reproduce the issue, assess impact, apply a proportionate fix and notify the reporter when appropriate. We do not promise a reward, public credit or fixed remediation deadline.

Security Incidents

If an incident affects personal information, we will investigate, contain and document the event and provide legally required notifications where applicable.

Privacy questions should be sent to [email protected]. Product-security issues affecting Kimi must be reported through official Moonshot AI channels.