Can’t be hijacked, can’t be reused
Every visitor gets a one-time pass that only works on your exact website, for a short window, then it’s gone.
Origin-locked, signed session tokens with short expiry.Security
Mr C runs directly on your site, next to your brand. Here’s exactly what stops it from ever becoming a liability.
Every visitor gets a one-time pass that only works on your exact website, for a short window, then it’s gone.
Origin-locked, signed session tokens with short expiry.The chat widget lives in its own sealed bubble on the page. Your website can’t break it, and it can’t touch your website.
Renders in a Shadow DOM inside a sandboxed iframe.It only responds on websites you’ve explicitly approved, so there’s no copying the script onto a random site to hijack your agent.
Exact-origin allowlisting. No wildcard matches.Answers come only from content you’ve approved. If it doesn’t know, it says so instead of inventing a confident-sounding guess.
Retrieval-grounded generation with an explicit no-answer fallback.When Mr C learns your site, it stays inside your domain, respects your robots.txt, and never follows a redirect off your property.
Origin-bounded crawler, robots.txt compliant, validates every redirect.API keys and model details never touch a visitor’s browser. All they ever get is a temporary, limited-use pass.
Provider credentials stay server-side; the client only receives a scoped session token.Every website Mr C serves is a separate, walled-off tenant. Your approved content, branding, and configuration are never visible to, or retrievable by, any other business we work with.
Have a specific security or compliance question? Get in touch and we’ll answer directly.