Beijing-based Z.ai, also known as Zhipu AI, has apologised to users of its ZCode programming platform, after developers found the tool was uploading their data to external cloud servers without their consent or knowledge.
The incident came to light on Friday when a technical blogger named Ferstar discovered encrypted files that had either been sent or were pending upload to Alibaba cloud servers.
According to filenames, one of the files contained a snapshot of a commercial project Ferstar was working on, including its Git project history.
Data upload
He said the archive couldn’t be opened by him or the ZCode client and could only be decrypted with a private key held on Z.ai’s back end.
The upload mechanism was enabled by default, with no means of turning it off, Ferstar said.
Other users reported similar behaviour.
In a statement on Friday, Z.ai said it had fixed the issue and apologised to affected users, saying it planned to open-source ZCode and would invite third-parties to review it.
“We welcome developers to continue reviewing ZCode and reporting potential issues,” Z.ai said in a statement.
Security concerns
It said all data uploaded had immediately been destroyed, although developers said over the weekend that there was no way of independently verifying this.
On Sunday, Z.ai said it would introduce a data non-retention policy for its model-as-a-service platform to prevent the persistent storage of user inputs and outputs, although certain data might be retained for API services or to satisfy legal requirements.
A software engineer at an unnamed leading Chinese robotics company told the that the company had banned the internal use of Z.ai’s tools over security concerns.
Z.ai’s popular GLM models can be used with its own ZCode programming tool or with competing offerings such as OpenAI’s Codex.