Origin, route, context, and widget key boundaries
Security and ops one-pager
AnswerLattice can use safe product context and reviewed sources without collecting secrets. Use this one-page summary for install reviews, developer handoff, intake reviews, and buyer security checks.
Origin, route, context, and widget key boundaries
What can be sent, what must never be sent
Drafts and generated content stay owner-approved
Restrict widget runtime config to the product and staging domains where AnswerLattice should run.
Hide the widget from auth, payment, admin, internal help, or other sensitive paths.
Send path, title, feature, workflow, role, and locale. Legacy fields are public-label compatibility only. Do not send secrets or raw customer records.
For plan- or role-sensitive support, sign a short-lived token on your server. AnswerLattice stores the public key only and never accepts workspace scope from token claims.
Allow exact HTTPS diagnostic hosts and attach at most three links. AnswerLattice does not fetch, embed, or use linked content as answer truth.
Import only owner-selected public pages, supported files, screenshots, or short recordings. Raw media is not retained by default, and generated output requires owner review.
Screenshots are user-initiated upload or paste only. The widget does not automatically capture the host app screen or scrape the DOM.
AnswerLattice validates widget keys by hash and can copy recoverable widget keys only from encrypted server-side key material.
Drafts, generated answers, and suggested changes do not become official support until reviewed.
Authorized owners can export a complete bounded package of approved knowledge. Tickets, chats, visitor details, keys, credentials, and audit logs are excluded.
Public widget config, search, feedback, predictive, and API paths are bounded and validated before expensive work.
Dashboard and runtime reads resolve AnswerLattice workspace scope server-side; client context is never trusted as tenant identity.
Workspace members use AnswerLattice-specific roles and owner-managed reset controls for support work.
Report security or data-handling concerns without sending secrets or full customer datasets in the first message.
Send stable labels that describe where the user is stuck: path, page title, feature, workflow, public role label, and locale. Legacy plan and entity hints must stay public labels only.
Do not send passwords, auth tokens, card data, private customer records, raw database IDs, emails, phone numbers, unrelated personal information, screenshots of screens that reveal secrets, or recordings that include private customer data.
The full security page covers hosted help, compiled context, scoped workspaces, role-scoped team access, ticket debugging context, and scheduler boundaries.