ME AI message: Shanmen Chengming Technology Co., Ltd. sent a letter to Beijing Zhipu Huazhang Technology Co., Ltd., raising multiple demands regarding alleged unauthorized uploading of the company’s data assets and trade secrets through its ZCode client, and reserving the right to pursue legal accountability. Chengming Technology stated that although Zhipu has publicly apologized for “the silent upload of users’ local repository data” and claimed that the issue has been fixed, Chengming Technology conducted independent evidence collection and found that the uploads were automatically triggered and occurred in batches. They were not merely “code snippets,” but complete archived files including the project’s full source code, system architecture, version control history, database passwords, cloud service credentials, and employees’ personal information—far exceeding the scope of data collection stated in its (privacy policy). In addition, although the client was updated to version 3.12.3 on September 16, uploads were still detected during the early hours of the day when Zhipu made its public apology, casting doubt on the actual effectiveness of the “fix.” Furthermore, the ZCode client’s network requests point to a Singapore entity, while the contracting entity under the service agreement is Beijing Zhipu Huazhang; the company is demanding clarification on the responsible party for this upload and whether any data was transmitted abroad or stored overseas. Chengming Technology requires Zhipu to provide a written response by October 10 and complete the following matters: immediately stop processing and thoroughly delete all uploaded data and related derived data, caches, and backups; provide a complete processing status checklist; explain the data destinations, whether the data is shared with third parties, whether it is used for model training, and whether any cross-border transmission occurs; explain how encryption private keys are stored and provide complete operation logs covering any access, downloads, or exports of the data; clarify the exact scope of “destruction” mentioned in the earlier public response; issue a certificate confirming deletion completion; provide a written commitment that it will not upload data without authorization again; legally provide explanations for individuals regarding how to access, copy, and interpret personal information; designate official communication and liaison channels; explain the responsible entity and the circumstances of data being transferred out of the country; and provide the original text of the previously published corrective action statement. At present, Zhipu has not issued a public response to the above letter. Further reading: Tracking the Zhipu ZCode code-stealing incident: Who audits the data behavior of the agent? (Source: ME)