Security

Trusted enough to sit on your homepage.

Mr C runs directly on your site, next to your brand. Here’s exactly what stops it from ever becoming a liability.

Zero data leaves your control Your data, fully isolated Cites its sources, or says nothing

Can’t be hijacked, can’t be reused

Every visitor gets a one-time pass that only works on your exact website, for a short window, then it’s gone.

Origin-locked, signed session tokens with short expiry.

Fully walled off from your site

The chat widget lives in its own sealed bubble on the page. Your website can’t break it, and it can’t touch your website.

Renders in a Shadow DOM inside a sandboxed iframe.

Only you decide where it runs

It only responds on websites you’ve explicitly approved, so there’s no copying the script onto a random site to hijack your agent.

Exact-origin allowlisting. No wildcard matches.

It won’t make things up

Answers come only from content you’ve approved. If it doesn’t know, it says so instead of inventing a confident-sounding guess.

Retrieval-grounded generation with an explicit no-answer fallback.

It only reads what it’s allowed to

When Mr C learns your site, it stays inside your domain, respects your robots.txt, and never follows a redirect off your property.

Origin-bounded crawler, robots.txt compliant, validates every redirect.

Your keys never leave the building

API keys and model details never touch a visitor’s browser. All they ever get is a temporary, limited-use pass.

Provider credentials stay server-side; the client only receives a scoped session token.

Your data stays yours

Every website Mr C serves is a separate, walled-off tenant. Your approved content, branding, and configuration are never visible to, or retrievable by, any other business we work with.

Have a specific security or compliance question? Get in touch and we’ll answer directly.