API protection

API Abuse Policy

How QFOXAI protects customer credentials, quota fairness, service capacity, billing integrity, and OpenAI-compatible API reliability.

EffectiveJuly 17, 2026
EvidenceRequest ID and timestamp
Compromised keyRevoke or rotate immediately
Appealsupport@qfoxai.com
Protective controls are intended to stop credential compromise, denial of service, unpaid consumption, policy violations, and unfair use while minimizing disruption to legitimate customers.
01

Credential responsibility

API keys must remain private and server-side. Activity made with a valid key is attributed to its owning account unless QFOXAI confirms another cause. Use separate keys for separate projects, apply expiry and IP restrictions where appropriate, and revoke a key immediately if it appears in public code, logs, screenshots, browser traffic, or an unauthorized device.

02

Traffic and quota abuse

Prohibited behavior includes intentional rate-limit evasion, rotating accounts or keys to bypass limits, unbounded retry loops, coordinated request floods, hidden resale, unauthorized proxying, unpaid consumption, or automated traffic that degrades service for others.

03

Scanning and interference

Do not probe, enumerate, scrape, reverse engineer, benchmark abusively, or attempt unauthorized access to QFOXAI infrastructure, internal routes, provider credentials, customer records, private model information, or security controls. Authorized security reports should use the published support channel and avoid accessing data beyond what is necessary to demonstrate the issue.

04

Content and downstream misuse

API customers must enforce the Acceptable Use Policy in their applications. Repeated unsafe requests, fraud, malware, non-consensual imagery, spam, privacy abuse, or attempts to defeat moderation may lead to model, key, project, or account restrictions even when traffic stays within numeric quotas.

05

Signals and investigation

QFOXAI may use request rate, token volume, status patterns, IP and key changes, account state, safety outcomes, payment signals, and other operational metadata to identify suspicious behavior. Investigations are based on risk and context; a single error does not automatically mean abuse.

06

Protective actions

Depending on risk, QFOXAI may return a clear error, reduce speed, hold a request, disable a model, revoke or quarantine a key, require verification, pause billing, remove public content, suspend a project, or restrict an account. Urgent threats, credential compromise, legal duties, or severe abuse may require immediate action without advance notice.

07

Recovery and appeal

If a key is exposed, revoke it, create a replacement, review recent usage, update the consuming application, and narrow permissions before restoring traffic. If you believe an action was incorrect, contact support@qfoxai.com with the account email, UTC timestamp, endpoint, public model alias, HTTP status, and QFOXAI request ID. Never include the full secret.