Allowed origins, blocked routes, safe context
Security
AnswerLattice uses safe page hints, explicit screenshot attachments, bounded source intake, allowed origins, blocked routes, compiled approved context, role-scoped workspaces, and owner-approved answers so support can be helpful without collecting secrets.
Allowed origins, blocked routes, safe context
Owner-selected intake, capped media extraction
Owner-approved answers before official guidance
Install the widget only on exact allowed origins and hide it from selected routes. Send safe page context instead of secrets. Keep screenshots user-initiated, use selected sources for Knowledge Intake, and approve support answers before they become official.
Open security one-pagerAnswerLattice is built around product-owned workspace boundaries, widget runtime controls, and reviewed support-knowledge access.
Widget config loads only from approved product and staging domains.
Route, feature, workflow, role, and plan hints guide support without secrets.
Auth, payment, admin, or sensitive pages can hide the launcher.
Support knowledge stays tied to the correct AnswerLattice workspace.
Public docs, FAQ, changelog, robots, and sitemap render without account data.
Drafts and proposals require review before becoming official answers.
Runtime bundles expose approved context, not raw tickets, drafts, audit logs, or API keys.
AnswerLattice documents use product, account, and workspace scope so support knowledge, tickets, widget settings, and summaries stay tied to the correct workspace.
AnswerLattice workspace members receive AnswerLattice-specific permission claims so team, billing, widget, knowledge, support, and answer-review controls can be separated by role.
Workspace owners can create a new temporary passcode and force sign-out for managed team members when access needs to be refreshed.
Widget context is designed for page, route, feature, workflow, role, and plan hints. Unsigned values are relevance hints only and should not include secrets, tokens, passwords, payment card data, or unrelated personal information.
A host product can sign short-lived plan, role, locale, and requester claims on its server. AnswerLattice stores only the public verification key, derives workspace scope from the widget key, and keeps generic support available when a token is invalid.
A product may attach up to three exact-host HTTPS links from its own support-safe diagnostics. AnswerLattice does not fetch, embed, crawl, or treat those links as answer truth.
Users can attach or paste screenshots when visual context helps. AnswerLattice does not automatically capture the host page, scrape the DOM, or write widget images to persistent storage.
Knowledge Intake accepts selected public links, supported files, screenshots, and short recordings as owner-provided evidence. URL import is bounded, media work is capped and credit logged, and raw media is not retained by default.
Workspace owners can restrict runtime admission to exact origins and hide the launcher on selected routes. Route hiding is a presentation control, not an authorization boundary.
Hosted help domains resolve through AnswerLattice-owned registry documents so anonymous docs, FAQ, changelog, robots, and sitemap pages never depend on client-supplied tenant IDs.
Tickets can include a capped, sanitized snapshot of recent browser context at creation time so owners can debug broken screens without asking customers for technical details.
Generated drafts, product candidates, and suggested changes require human review before they become active approved answers.
Ready runtime bundles contain approved public-safe context for enabled readers and server-only private context for authenticated paths. The current widget remains server-mediated. Drafts, tickets, audit logs, API keys, and raw signals stay out.
Operational logs are meant for reliability, failure analysis, and abuse protection. Production flows should avoid storing raw sensitive payloads.
Authorized owners can export approved product structure and support knowledge through a rate-limited, size-capped JSON response. Tickets, conversations, visitor identity, secrets, raw keys, and audit logs are excluded.
AnswerLattice uses AnswerLattice-owned dashboard routes, constants, schedulers, widget configuration, and workspace data boundaries.
Source intake boundary
Use public product or docs pages you select, supported files, screenshots, and short recordings that are safe to process. AnswerLattice does not crawl an entire private app, retain raw media by default, or make generated intake output official without owner review.
Page context boundary
Use page, route, feature, workflow, role, plan, or state names. Do not send passwords, tokens, payment data, private customer records, or unrelated personal data. If users attach a screenshot, keep it deliberate and avoid pages that show secrets.
Safe context
Allowed page context can guide support while secrets, payment data, and private records stay outside the widget packet.
Route, workflow, role, plan, and product area can guide support.
AnswerLattice uses bounded context for answer relevance.
Tokens, card data, passwords, and private records stay out.
Trust controls
These controls map to the implemented AnswerLattice runtime: dashboard APIs, widget config, widget search, feedback, tenant-scoped rules, summaries, and owner review queues.
AnswerLattice management routes resolve an AnswerLattice product account and workspace before reading or writing workspace data.
AnswerLattice team access uses product-specific roles for support, knowledge, widget, billing, answer review, and workspace controls.
The widget is designed to be installed on selected product pages, not sprayed across every route by default.
AnswerLattice can publish reviewed support content on support domains without exposing authenticated support operations.
AnswerLattice keeps ticket debugging context useful by tying it to the reported issue instead of broad background collection.
AnswerLattice treats page context as a hint for support relevance, not as trusted identity or tenant scope.
Products that need plan- or role-sensitive support can verify those claims without trusting browser identity or importing a session-replay system.
Screenshots can help explain a broken screen, but they should remain a deliberate user action instead of background collection.
Intake is designed to teach AnswerLattice from selected sources without creating a crawler, private connector, or automatic publishing path.
Support correctness comes from approved knowledge, not automatic rewriting.
AnswerLattice keeps high-cost and public runtime paths bounded so one noisy widget cannot become an uncontrolled backend workload.
AnswerLattice separates reviewed source data from runtime context so public and authenticated consumers receive only the approved fields they need.
Support Truth Export is intentionally narrower than a full workspace backup so approved knowledge can move without exposing private support operations.
Daily support review work is centralized and workspace-aware rather than split into many scheduled functions.
AnswerLattice keeps its product data and support runtime bounded to AnswerLattice workspace, widget, hosted help, and answer review surfaces.
Report security, privacy, or data-handling concerns to the AnswerLattice team. Do not include secrets, production credentials, or full customer data in the first message.
hello@answerlattice.com