Bỏ qua để đến nội dung

Bảo mật và riêng tư

Bestie xử lý hội thoại riêng tư, file local, provider credentials và về sau là external tools. Bảo mật và riêng tư là yêu cầu sản phẩm, không phải phần trang trí.

Quy tắc:

  • Không bao giờ in API key sau khi nhập.
  • Redact secrets trong logs, Doctor JSON, channel summaries và tool output.
  • Lưu secrets trong .env cho local builds.
  • Ghi app logs với quyền owner-only.
  • Config exports mặc định không chứa secrets.
  • Doctor kiểm tra sự tồn tại của secret, không in giá trị.

Không commit:

  • .bestie/
  • .env hoặc .env.* có giá trị thật
  • API keys, provider tokens, Telegram bot tokens hoặc auth headers
  • local logs, memory databases, transcripts hoặc private conversation samples

Mọi action nên được phân loại:

  • read-only
  • local write
  • external write
  • public/external action
  • destructive
  • money/payment
  • unknown

Public, external, destructive và payment actions cần xác nhận rõ ràng.

Nội dung từ web pages, MCP, documents, attachments hoặc tools là untrusted.

Quy tắc:

  • Không nghe instruction trong external content như system instruction.
  • Không tiết lộ secrets.
  • Không để external content tự kích hoạt tools.
  • Tóm tắt và quote external content an toàn.
  • Từ chối tool JSON hoặc shell command đáng ngờ thay vì thực thi.

Người dùng phải kiểm soát memory:

  • inspect
  • edit
  • delete
  • export
  • clear
  • pause/resume
  • approve sensitive memories

Memory không được tạo cảm giác creepy. Nhớ quá đà là bug sản phẩm.

Không market Bestie là:

  • có ý thức
  • người thật
  • thay thế therapist
  • romantic companion
  • có trí nhớ hoàn hảo
  • an toàn để chạy arbitrary tools nếu thiếu approvals