arrow_back
All program documents
Technical Conditions and Security Policy
This English version is provided for convenience only. The Turkish text is authoritative; in case of any discrepancy the Turkish version prevails.
In short
The program runs on Windows 10/11 (64-bit) and on Macs with Apple Silicon processors. Sharing requires at least 6 GB of graphics memory (at least 8 GB of unified memory on a Mac) and a certain internet speed; Windows computers without a suitable graphics card can run in processor mode only for your own use and test requests. Your computer does not open any port; all connections are encrypted and go from you to our servers. Updates are not installed automatically; sharing does not start below the minimum supported version.
This summary is only meant to make reading easier; the numbered clauses below are binding.
1. Purpose and Scope
1.1
This Technical Conditions and Security Policy (the “Policy”) describes the hardware, operating system and connection requirements for the Onysoft AI Gateway Node program to operate within the Onysoft GPU Sharing Program; the sharing, version and update rules; the program's security architecture; and the participant's security responsibilities.
1.2
The Policy forms an integral part of the Individual Participation Agreement and the Corporate Participation Agreement.
1.3
The thresholds and ratios in this Policy are the values in force on its effective date. Onysoft may update these values through the program configuration for the secure and efficient operation of the program; material changes unfavourable to participants are announced in accordance with the amendment provisions of the agreements.
2. Supported Operating Systems
2.1
The program runs on the following systems:
| Platform | Requirement |
|---|---|
| Windows | Windows 10 or Windows 11, 64-bit (x86-64) |
| macOS | macOS 13.3 (Ventura) or later, Apple Silicon (M series) processor. Macs with Intel processors are not supported. |
2.2
Other operating systems are not supported.
2.3
Even if the program runs on operating system versions whose support has ended, it should not be used on systems that no longer receive security updates.
3. Hardware Tiers
3.1
The program measures the device's hardware and determines a tier. The tier is recalculated on our servers from the measurements reported by the device; which models can be run and eligibility for sharing depend on this tier.
3.2
Devices running on a graphics card (GPU):
| Tier | Mac (unified memory) | Windows (graphics memory) |
|---|---|---|
| Entry | 8 GB or more | 6 GB or more |
| Medium | 16 GB or more | 12 GB or more |
| Strong | 32 GB or more | 24 GB or more |
| Very strong | 64 GB or more | 48 GB or more |
| Insufficient | Below 8 GB | Below 6 GB or integrated graphics |
3.3
On Windows, NVIDIA graphics cards are supported with CUDA and discrete AMD and Intel graphics cards with Vulkan; Vulkan support is experimental. Graphics integrated into the processor are not supported.
3.4
Windows computers whose graphics card is not suitable for sharing can run in processor (CPU) mode if they meet the following conditions:
- (a)64-bit Intel or AMD (x86-64) processor;
- (b)AVX2 instruction set support in the processor;
- (c)at least 8 GB of system memory.
3.5
In processor mode, at most one model can run at a time and only models with a file size not exceeding 5.5 GB can be used. Responses are produced noticeably more slowly than on a graphics card. Devices in processor mode are used only for your own use and Onysoft test requests; no customer requests are sent to them.
3.6
Sufficient free disk space is required for model files. The space needed ranges from a few gigabytes to tens of gigabytes depending on the selected model; the program shows the required space before installation.
4. Network Requirements
4.1
To start sharing, the internet connection must meet the following minimum values:
| Measurement | Minimum value |
|---|---|
| Download speed | At least 10 Mbps |
| Upload speed | At least 5 Mbps |
| Latency (to Onysoft servers) | At most 150 ms |
4.2
Connection measurement (speed test) is performed only against Onysoft's own servers; no third-party speed test service is used. One measurement downloads about 10 MB of data (3 MB on slow connections), uploads 5 MB and performs five latency measurements.
4.3
The program only establishes outbound encrypted (HTTPS) connections. No port needs to be opened for incoming connections and no port forwarding is required on the modem or firewall. On corporate networks, outbound HTTPS access to Onysoft servers, github.com and huggingface.co must be allowed.
4.4
Because model files are large, a significant amount of data is downloaded on first installation and when new models are added. On metered connections the participant should take this usage into account.
5. Sharing Intensity and Resource Use
5.1
The participant can select Low, Balanced or High sharing intensity in the program; the default is Balanced. The intensity determines the memory budget that can be allocated to models and, in processor mode, the number of threads used.
5.2
Values in force on the effective date:
| Intensity | Share of usable memory allocated to models | Threads in processor mode |
|---|---|---|
| Low | 60% | Half of the cores |
| Balanced | 80% | Number of cores minus one |
| High | 95% | All cores |
5.3
Usable memory is calculated as follows:
- (a)Mac: 66% of unified memory on devices with 36 GB or less, 75% on larger devices;
- (b)Windows (graphics card): graphics memory remaining after 768 MB reserved for the operating system;
- (c)Windows (processor mode): system memory remaining after 4 GB reserved for the operating system and other programs.
5.4
On devices running on a graphics card, up to three models can be kept ready at the same time; in processor mode, one model.
5.5
Sharing can be turned off in the program at any moment. No jobs are sent to the device while sharing is off.
5.6
The program does not change the device's fan speed, power settings or temperature limits. Monitoring the device's thermal and power condition and lowering the intensity or turning sharing off when necessary is the participant's responsibility.
6. Versions, Updates and Minimum Supported Version
6.1
Program versions are numbered in the form “major.minor.patch” (for example 0.4.0). Each version is published in the Dashboard with its file size, SHA256 hash, release date and release notes.
6.2
The program checks for a new version at start-up and at regular intervals while running. When a new version is published, the program notifies you and offers to open the download page. Updates are not downloaded or installed automatically.
6.3
Onysoft sets a minimum supported version for reasons of security, compatibility or correct operation of the program. On programs below the minimum supported version, sharing is not started, our servers do not assign jobs to such devices, and the program tells the participant to update.
6.4
Before the minimum supported version is raised, an announcement is made in advance via the Dashboard and e-mail wherever possible. Where a serious security vulnerability must be fixed, the minimum version may be raised immediately without prior announcement.
6.5
The minimum version check is a compatibility check based on the version reported by the program. Where security requires, Onysoft may also revoke the access keys of affected devices and ask for the device to be paired again with a current version.
6.6
The participant is obliged to install published updates within a reasonable time. An update is made by installing the new version over the existing program; settings, the device link and downloaded models are preserved.
7. Verifying the Installation File
7.1
The program currently does not carry an operating system code signature. Therefore, at first launch you may see an “unidentified developer” warning on macOS or a SmartScreen warning on Windows. The program should only be downloaded from the Dashboard.
7.2
The SHA256 hash of the downloaded file should be compared with the value published in the Dashboard:
- (a)macOS: the command “shasum -a 256 <file name>” in Terminal;
- (b)Windows: the command “Get-FileHash <file name> -Algorithm SHA256” in PowerShell.
7.3
If the hash does not match, the file should not be opened; it should be deleted and the matter reported to info@onysoft.com.
8. Security Architecture
8.1
The program is designed according to the following security principles:
- (a)Outbound connections only: the device does not open any port accepting connections from outside; the program establishes encrypted (HTTPS) connections to our servers and receives jobs over them.
- (b)Local model server: models serve only on the 127.0.0.1 address reachable from within the device itself; other devices on the local network cannot access this server.
- (c)Device pairing: the device is linked to the account by confirming in the Dashboard a code shown by the program that is valid for 10 minutes. Device pairing is only possible for accounts with an approved application.
- (d)Key storage: the device access key is stored encrypted in the Keychain on macOS and with the per-user data protection facility (DPAPI) on Windows. Our servers keep only an irreversible hash of the key.
- (e)File integrity: runtime and model files are downloaded only over HTTPS and are not used unless they match the SHA256 hash published by Onysoft.
- (f)Separation of rights: own-use requests can only be sent from the account the device is linked to; no other account can send requests to your device.
- (g)Limited access: the program works only with files in its own folder; it does not access other files on the device and has no remote command execution function.
- (h)Log security: the program log is kept on the device up to 5 MB and contains no secret keys.
8.2
The program determines which runtime and model files to download according to the configuration it receives from our servers. The security of this configuration is therefore Onysoft's responsibility; Onysoft includes in it only files from verified sources together with their SHA256 hashes.
8.3
Program data is kept in the “~/Library/Application Support/OnysoftNode” folder on macOS and the “%APPDATA%\OnysoftNode” folder on Windows.
9. Participant's Security Responsibilities
9.1
The participant:
- (a)keeps the operating system, graphics drivers and security software up to date;
- (b)uses a strong and unique password for the Onysoft AI Gateway account and enables two-step verification;
- (c)uses a screen lock on the device and takes the necessary precautions when leaving the device available to others;
- (d)downloads the program only from the Dashboard and verifies the SHA256 hash of the installation file;
- (e)does not copy files in the program folder, in particular the device access key, to other devices;
- (f)signs out of the program before disposing of the device;
- (g)turns sharing off and notifies Onysoft upon noticing anything suspicious.
10. Reporting Security Incidents
10.1
If the device is lost or stolen, the account is suspected to be compromised, the program behaves unexpectedly or the hash of the installation file does not match, the participant turns sharing off and notifies info@onysoft.com without delay. Upon notification, Onysoft may revoke the access key of the relevant device.
10.2
If Onysoft detects a security incident in the program infrastructure affecting participants, it takes the necessary measures and informs the affected participants. If personal data is obtained by others through unlawful means, the data subjects and the Personal Data Protection Board are notified as soon as possible under Article 12(5) of KVKK.
11. Changes
11.1
This Policy may be updated in accordance with the amendment provisions of the participation agreements. The current version is published on this page with its version number and effective date.
Data controller and contact
Onysoft Veri Merkezi Sistemleri Yazılım Sanayi ve Ticaret A.Ş.
Address: İTOB OSB Mah. 10032 Sk. No: 2 İç Kapı No: Z13, 35470 Menderes / İzmir
Tax office and number: Menderes Vergi Dairesi — 6440947328
E-mail: info@onysoft.com
Phone: 0850 302 3021
Address: İTOB OSB Mah. 10032 Sk. No: 2 İç Kapı No: Z13, 35470 Menderes / İzmir
Tax office and number: Menderes Vergi Dairesi — 6440947328
E-mail: info@onysoft.com
Phone: 0850 302 3021
Other program documents
- Individual Participation Agreement (version 1.0)
- Corporate Participation Agreement (version 1.0)
- GPU Sharing Program Privacy Notice (KVKK) (version 1.0)
- Acceptable Use Policy (version 1.0)
- Explicit Consent and Commercial Electronic Message Permission (version 1.0)
This document is confirmed electronically in the dashboard during application. At the moment of confirmation, the document identifier, version, date and time, IP address and browser information are recorded. You can keep a copy of the version you confirmed as a PDF using the Print button on this page.