AI Server is closed by default: it serves only its own computer until you give it a paid licence and an API key, and it refuses to serve the network without keys. Use this list when you open it up.

Access

  • One API key per person, device and app. Label them so the usage report makes sense.
  • Set expiry on keys given to contractors, pilots and demos (--expires-days).
  • Narrow keys used by a single application with model and endpoint allowlists.
  • Give Allow server administration only to monitoring tools and operators; review keys that predate the separate admin right.
  • Revoke keys you no longer recognise on the Usage page.

Network

  • Serve the smallest scope you need: this computer, then the LAN; avoid Every network unless IPv6 clients need it.
  • Use HTTPS on any network you do not fully control (TLS).
  • Behind a reverse proxy, set AISUITE_TRUST_PROXY=1 and AISUITE_TRUSTED_PROXIES to the proxy's addresses. Never trust forwarded headers on a directly reachable server.
  • In a farm, let only the gateway reach the workers (the Helm chart's NetworkPolicy, or a firewall rule). Verify it with a request from another host.
  • Allow browser access only for the origins that need it (AISUITE_CORS_ORIGINS), never * on a server reachable from the internet.
  • Do not expose the legacy local-AI API on port 11434 to the network; it has no keys. It ends on 2026-12-31.
  • Allow outbound HTTPS to registration.softwaretailor.com for licensing, and to model sources for downloads; nothing else is needed.

Governance (Commercial)

  • Set rate limits per key and per client address.
  • Set daily quotas and monthly budgets on keys handed to teams you do not run.
  • Use Curated mode if users must not download models of their own choosing, and the model lifecycle to approve or block models.
  • Turn on content rules or moderation where your policy requires them.

Secrets

  • Mount the licence key as a file (AISUITE_LICENSE_KEY_FILE), never as an environment value.
  • Keep gateway.json (worker keys) and governance/audit-signing-key.json in secret storage.
  • Encrypt backups of the data folder.

Operations

  • Run the Windows server as a service, or the container with a restart policy, so it comes back after a reboot.
  • Keep the app and images up to date (upgrades).
  • Alert on "no healthy workers" and on scrape failures (monitoring).
  • Export and verify the signed audit log on the schedule your auditors expect.
  • Keep the provider credentials page empty unless an operator has decided to send some requests to a cloud model.

What the server does without being asked

  • Stores API keys as salted PBKDF2-SHA256 hashes and shows each key once.
  • Slows down clients that repeatedly present wrong keys.
  • On a server bound to this computer, answers only requests addressed to localhost, 127.0.0.1 or [::1], which blocks DNS-rebinding attacks from web pages.
  • Refuses to fall back to plain HTTP on the network when HTTPS was requested but the certificate is unusable.
  • Redacts keys and secrets from logs, including keys sent in a WebSocket URL.
  • Writes keys, gateway configuration and its lock file readable by their owner only on Linux.
  • Keeps prompts and answers out of logs, usage records, audit files and telemetry.

See security for the design behind these.