openimsdk / open-im-server

IM Chat
https://openim.io
Apache License 2.0
13.72k stars 2.42k forks source link

[Other]: Security audit and certification issue #2160

Closed radmirkashapov closed 5 months ago

radmirkashapov commented 5 months ago

What would you like to share?

Hi there! Has this solution been audited for security by any commercial or government organizations? Or maybe there were any certifications?

Additional information

No response

kubbot commented 5 months ago

Hello! Thank you for filing an issue.

If this is a bug report, please include relevant logs to help us debug the problem.

Join slack 🤖 to connect and communicate with our developers.

cubxxw commented 5 months ago

@radmirkashapov Do you have any special needs

radmirkashapov commented 5 months ago

@radmirkashapov Do you have any special needs

First of all, we would like to understand how the OpenIM solution works with personally identifiable information (PII) and other confidential information that may potentially be contained in messages. Among the problems I can highlight the use of user messages to train AI models, the statistics collected, the lack of e2e encryption, and so on. We would like to see a separate page in the documentation on this issue with a description of the data flow in the system. The main question specifically for this issue is to clarify whether such an audit was conducted by someone from the outside? Thank you for your attention.