記錄由你確認
Subscriptions, amounts, currencies, and dates come from your input. TutuSub does not read bank transactions or present planning summaries as final invoices.
安全與資料
下面說明哪些資料由你維護、哪些憑證會被保護、外部請求如何受限,以及發生異常時系統和使用者分別需要做什麼。
Subscriptions, amounts, currencies, and dates come from your input. TutuSub does not read bank transactions or present planning summaries as final invoices.
HTTP Pull 等上游認證配置在服務端使用 AES-256-GCM 加密;部署缺少有效主金鑰時,新的敏感憑證寫入會被明確拒絕,而不是靜默明文儲存。
通用 Webhook 支援簽名與時間戳校驗,並對重放做去重。URL、token 和金鑰都不應出現在公開前端程式碼或聊天記錄中;洩露後應立即輪換。
HTTP Pull 預設攔截私有、環回、鏈路本地等目標,禁止 URL 內嵌賬號密碼,並且不跟隨重定向,降低 SSRF 與跳轉繞過風險。
拉取請求有超時和 1MB 響應限制;Webhook 有 256KB 請求體限制與速率限制。超限請求失敗,不應持續佔用記憶體或工作執行緒。
連線失敗會留下錯誤狀態,後續成功檢查可恢復。入站事件有回執去重,通知傳送中的中斷任務也有後臺恢復路徑;使用者仍應保留原平臺作為最終事實來源。
Disabling or deleting a record in TutuSub does not cancel it at a registrar, SaaS vendor, cloud provider, or payment institution. Confirm every payment, refund, contract, and auto-renew change at the original service.