Customers approve the pages and documents the agent can use before publish.
Security
Source approval, domain controls, and instant pause from day one.
Atithya builds trust with practical controls: approved sources, tenant separation, sensitive connection details outside the browser, rate limits, usage caps, retention, deletion, incident review, and instant pause.
Practical trust controls
Security is a customer-visible operating system, not a promise hidden in a footer.
Live agents answer only on approved customer, preview, and development surfaces.
Sensitive connection details stay outside the browser while visitors only see the approved agent experience.
Agent knowledge, leads, transcripts, and settings are scoped to the owning customer.
Request controls reduce abuse without making genuine visitors feel blocked.
Answer allowance and alerts keep spend predictable while lead capture remains available.
Out-of-scope prompts, unknown domains, and repeated suspicious activity are redirected through safe review paths.
The customer can pause an agent immediately while keeping a visitor-friendly handoff path.
Domain allowlist
Plans define where the agent is allowed to answer.
- demo environment allowed
- localhost only in development
- unknown domains blocked
- per-domain usage metering
Incident response
Severity is defined before something goes wrong.
Data handling
Conversation retention and deletion need a visible workflow.
Keep transcripts for analytics and quality review only as long as the customer policy allows.
Customer requests should remove leads, transcripts, source snapshots, and agent settings from the active workspace.
Response flow
Every incident should create a diagnosis trail.
- pause agent if needed
- notify Sherry immediately
- preserve safe logs
- diagnose cause
- fix knowledge, guardrail, or config
- re-run QA
- republish
- send customer note if needed
What matters
Trust language stays evidence-backed.
Atithya describes practical controls clearly, without making HIPAA, SOC 2, ISO, or GDPR claims before the programs, terms, and reviews support them.
Shows approved sources, domain allowlists, rate limits, incident response, data handling, and instant pause.
Trust comes from practical controls and accurate non-claims, not inflated compliance language.
- Source approval
- Allowed domains
- Rate limits
- Pause-first incident flow
Approved source control
Customers approve what the agent can use before publish, and noisy content like blogs can be excluded by default.
Domain allowlist
Free supports one customer domain, Pro two, Plus five, and Custom as agreed. Demo and localhost are controlled separately.
Connection detail protection
Sensitive connection details stay outside the browser while visitors only see the approved agent experience.
Incident response
Pause the agent, preserve safe logs, diagnose the issue, fix configuration or knowledge, rerun QA, and republish.
Workflow
Launch controls
Security is treated as an operating control: approve sources, restrict domains, monitor incidents, and pause answers when needed.
- Source approval
- Domain allowlist
- Connection detail protection
- Tenant metering
- Rate limiting
- Usage caps
- Retention
- Deletion
Product principle
Evidence-backed trust language
No formal HIPAA, SOC 2, ISO, or GDPR claims until the product, process, legal terms, and audits support those statements.