A packaged AI assistant needed to survive being handed to strangers,
so access got a default rate limit from day one
An AI assistant meant to be sold and run by someone else cannot assume its new operator will configure abuse protection correctly.
Task
SENET is packaged with documentation so a buyer can run it themselves. That means the assistant has to arrive already protected against runaway usage and unauthorised access, not rely on a new operator to add that later.
What we did
Every API key is authenticated and capped by default at 60 requests per hour. The FastAPI backend enforces the limit before a request reaches the model cascade or the memory engine. An admin key and a kill switch sit behind that, so unauthorised operations can be shut down without redeploying.
Result
A buyer gets an assistant that is safe to expose, with sane defaults already in place. There is no bare API they have to wrap in their own protection before going live. It is one of the guardrails that let us sell SENET as a packaged product rather than support it as a managed service.
Full story: SENET: a sellable AI assistant with its own memory engine and a self-training router. Want the same? Get a plan.