Updated on 2026-09-20 GMT+08:00

Security Overview

Huawei Cloud MaaS builds inference security capabilities based on observability, analyzability, and controllability, providing you with clear visibility and full control over your service and data security.

Figure 1 MaaS security overview

Observability

  • Cloud Trace Service (CTS)

    Operations such as model service provisioning, API key creation/deletion/editing, and endpoint creation/deletion/editing are reported to CTS. This supports security analysis, compliance audit, resource tracing, and fault locating. For details, see Operation Audit and Model Monitoring.

  • Cloud Eye

    MaaS interconnects with Cloud Eye to monitor real-time services and their model loads, including metrics such as RPM/TPM, token usage, and model call success/failure rates. It also supports metric dashboard visualization. For details about the metrics, see Metrics.

  • Model Call Statistics

    This feature collects call data of built-in services and endpoints within a specified period, including the total number of tokens called, number of input tokens, number of output tokens, and end-to-end latency. It displays data trends at a minimum granularity of minutes, helping you understand service usage and performance changes for more effective model evaluation, problem locating, fault rectification, and performance optimization. For details, go to the Call Statistics page.

Analyzability

  • Threat Detection

    Proactively identifies threats and intrusions and generates alarms.

  • Security Event Tracing

    Aggregates security logs, displays the threat situation, and supports end-to-end backtracking and locating of security events.

  • Abnormal Event Alarms

    Configures alarms for rate limiting and abnormal requests by using SMN, and sends alarms by SMS, email, or voice.

Controllability

  • API Key
    • Supports restricting the IP address whitelist for API calls and the access scope of model services. When creating an API key, you can specify the access scope of resources.
      Figure 2 API key permission settings

    • Periodic rotation: You are advised to periodically create and use new API keys and delete old API keys.
    • The plaintext is only displayed once during creation. The platform does not store the plaintext. If the plaintext is lost, it cannot be restored. You are advised to import the plaintext to CSMS or DEW immediately.
    • You are advised to isolate credentials by application or environment. Different applications and environments use independent API keys.
  • Content Moderation

    Input/Output text, image, and video moderation is supported. Text moderation supports sensitive word detection and semantic detection of political, sensitive, terrorism-related, prohibited, abusive, and advertising content. Customers at V2 or higher levels can enable or disable this function.

    Figure 3 Switch for ModelArts Guard (AI guardrails)

  • Endpoint

    With endpoints, you can set up independent access paths, enforce rate-limiting rules, and track costs precisely by endpoint name. This keeps your services stable and your costs optimized. When creating an endpoint, you can configure rate limiting and apply finer limits based on time segments.

    Figure 4 Rate limiting

  • Operation Permissions

    Fine-grained control is provided for the permissions to add, delete, and modify user-level API keys to prevent unauthorized IAM users from deleting or editing API keys. For details, see Managing API Key Operation Permissions of IAM Users.

Link Security

  • Public Network Link

    HTTPS/TLS encrypted transmission is supported for public network access. Models can defend against prompt injection attacks and command injections. MaaS provides built-in WAF, Advanced Anti-DDoS (AAD), vulnerability scanning, and situational awareness to provide intrusion detection and security defense capabilities.

  • Private Network Link

    VPC Endpoint (VPCEP) is used to access the service through a unidirectional private network channel, so that data is not exposed to the public network. For details, see MaaS Access Through a Private Network.

  • Compliance Certification

    Huawei Cloud strictly complies with data security regulations in and outside China and has obtained authoritative certifications in and outside China (the cloud platform has obtained the DJCP MLPS L4 certification, ensuring classified protection of cybersecurity). For details, see Certificates.