AI 0.1.95 / Security
AI diagnostics, privacy, and security
Review usage and failures without exposing prompts, responses, or provider credentials.
What Diagnostics records
Open Cointacted → AI → Diagnostics to review aggregate requests, tokens, actors, outcomes, and sanitized recent failures. Activity records omit prompt text, response text, API keys, authorization headers, and raw provider payloads.
Support and migration bundles also omit credentials. Review a bundle before sharing it because site names, plugin versions, and operational metadata may still identify the installation.
What leaves the site
For a real provider request, the selected provider receives the prompt, system instruction, enabled bounded conversation context, and any administrator-approved sanitized add-on context needed to answer. Provider billing, logging, regional processing, and retention follow that provider’s terms.
Production safeguards
Keep credentials in wp-config.php, use HTTPS, restrict access before setting quotas, and review every official add-on context source. Unsafe endpoints, unknown tools, unavailable capabilities, mutating recommendations, and unapproved context are rejected.
After any credential rotation, run the connection test and inspect Diagnostics. Deactivate AI or switch to Demo mode if failures begin exposing unexpected data in a provider response; raw content is not written to the diagnostics log, but the response still reached the requesting browser.
