Security
The Security page is where you protect an assistant from abuse: you choose where it can run, stop spam, moderate what visitors send, and manage banned visitors. Sensible defaults are already in place — open this page to tighten them for your use case.
Where to find it
- Open Administration → My Assistants → [your assistant].
- Go to Settings → Security.
At the top you'll see live counters — Active bans, Violations (24h) and Permanent bans — so you can spot a problem at a glance. The page is organized into four tabs: Domains, Anti-Spam, Moderation and Bans.
Domains
Controls which websites are allowed to load and use your assistant.
- Click Add Domain and enter each domain where your assistant should appear (for example,
example.com). - Leave the list empty to allow it everywhere.
This is the simplest way to stop other people from embedding your assistant on their own sites.
Add every domain your widget runs on — your main site, staging, and any landing pages — or visitors there won't be able to chat.
Anti-Spam
Stops a single visitor from flooding your assistant with messages.
Protection level — pick how strict the limits are:
| Level | What it does |
|---|---|
| Relaxed | Looser limits, fewer interruptions |
| Moderate | Balanced — a good default |
| Set your own limits | Define the exact number of messages allowed per minute, per 5 minutes, per hour and per day |
When the limit is reached — choose what happens:
| Action | What it does |
|---|---|
| Notify only | No restriction — just alerts you |
| Progressive ban | Gradually increases restrictions on repeat offenders |
| Immediate ban | Bans on the first critical violation |
Notifications:
- Notify on violation — get a notification when a rate limit is exceeded.
- Notify on ban — get a notification when a visitor is automatically banned.
Start with Moderate and only switch to custom limits or Immediate ban if you actually see abuse — limits that are too strict frustrate genuine users.
Moderation
Scans every incoming message with AI moderation before it reaches your assistant, so harmful content is caught early. It's free and adds only a fraction of a second of latency.
- Enable content moderation — turn the AI scan on or off.
- Zero-tolerance categories — the most serious categories (such as sexual content involving minors, and illicit/violent content) always trigger an immediate permanent ban, regardless of the settings below.
Detection level — how sensitive the scan is:
| Level | What it does |
|---|---|
| Relaxed | Higher thresholds, fewer false positives |
| Moderate | Balanced — recommended default |
| Strict | Aggressive blocking on borderline content |
When a message is flagged — choose the response:
| Action | What it does |
|---|---|
| Block message only | Reject the message, no ban created (recommended to start) |
| Progressive auto-ban | Block, then escalate the ban (5 min → 1 h → 24 h → permanent) |
| Immediate permanent ban | Block and permanently ban on the first violation |
- Notify on flag — send an admin notification each time a message is flagged or an auto-ban is created.
An Activity panel shows how moderation is performing: messages flagged (24h), auto-bans triggered, and the top category. Use View events for the full log.
Bans
Review and manage visitors who have been blocked — manually, or automatically by the anti-spam and moderation rules.
- Filter by Active bans, All bans, Expired or Permanent, and search by reason.
- Each ban shows its source — Manual or Automatic (anti-spam) — along with the reason, violations, identifier and when it expires.
- A visitor can be identified by IP address, user account, browser signature (fingerprint) or platform account.
- Click Add ban to block someone yourself, with a reason and a duration (temporary or permanent).
- Remove a ban to let that visitor use the chat again — this unbans the identifier and clears the cache.
Banning by IP address or browser signature can affect more than one person if they share a network or device. Prefer banning by user/platform account when you can.
Recommended starting point
| Tab | Suggested setup |
|---|---|
| Domains | List your own website(s) so only you can embed the assistant |
| Anti-Spam | Moderate level, with Notify on ban enabled |
| Moderation | Enabled, Moderate detection, Block message only to start |
| Bans | Leave empty — let auto-ban fill it, and review it if you get alerts |
Adjust from there as you learn how your assistant is used in the real world.