Security & privacy

Trust should be verifiable, not just branded.

This page summarizes the controls KINGAI Security uses or requires around updates, threat intelligence, quarantine, product claims and release evidence.

Official trust center: aq.kingai.work
S

Signed update manifests

Windows application updates use Ed25519 signatures, SHA-256 payload identity, HTTPS and required signed expiration.

T

Threat intelligence validation

Windows Threat Packs and Android Threat DB feeds are designed with signature, schema, version, expiry and rollback gates.

Q

Quarantine integrity

Recovery workflows verify stored content identity rather than assuming a quarantined payload remained unchanged.

R

Release evidence

Commercial Stable is blocked until exact release commits have required CI, signing, compatibility, device and corpus evidence.

P

Privacy-aware scope

Android DNS protection does not claim HTTPS decryption; product design avoids inventing surveillance capability for marketing.

C

Capability truth boundaries

Kernel interception, cloud reputation, runtime YARA-X or production ML are not presented as shipping unless objectively implemented and validated.

Release integrity

Windows and Android are currently Production Candidates. The release pipelines are intentionally fail-closed: a queued job, a job with no executed steps, a missing signing secret or a missing real-device approval cannot be converted into a pass by documentation.

A Commercial Stable label requires evidence bound to the exact release commit. Marketing text, a tag or a manually toggled flag is not enough.

Threat intelligence

Windows production feeds verify signed manifests before commercial publication. Android release validation mirrors the client Threat DB protocol and verifies the live production manifest before JKS signing and release builds.

Privacy and network behavior

Android web protection is DNS-only using a local VPN. It does not install a user certificate authority and does not claim HTTPS content inspection. Windows realtime protection is user-space monitoring of selected high-risk locations, not kernel-level full-disk interception.

Security reporting

Security issues can be reported through the repository security guidance or by contacting vip@kingai.work. Do not include active malware samples or credentials in ordinary email.

Need a product or security answer?

Use the FAQ for install and capability questions, or contact KING AI for business/security coordination.

aq.kingai.work