Atithya AIAccess

Security

Source approval, domain controls, and instant pause from day one.

Atithya builds trust with practical controls: approved sources, tenant separation, sensitive connection details outside the browser, rate limits, usage caps, retention, deletion, incident review, and instant pause.

P0pause-first incident posture
Agent live
Domain allowlist
Instant pause
Incident trail
Data deletion

Practical trust controls

Security is a customer-visible operating system, not a promise hidden in a footer.

Pause-first posture
Approved source control

Customers approve the pages and documents the agent can use before publish.

Domain allowlist

Live agents answer only on approved customer, preview, and development surfaces.

Sensitive connection handling

Sensitive connection details stay outside the browser while visitors only see the approved agent experience.

Tenant isolation

Agent knowledge, leads, transcripts, and settings are scoped to the owning customer.

Rate limiting

Request controls reduce abuse without making genuine visitors feel blocked.

Usage caps

Answer allowance and alerts keep spend predictable while lead capture remains available.

Abuse prevention

Out-of-scope prompts, unknown domains, and repeated suspicious activity are redirected through safe review paths.

Instant pause

The customer can pause an agent immediately while keeping a visitor-friendly handoff path.

Domain allowlist

Plans define where the agent is allowed to answer.

Free1 customer domain
Pro2 customer domains
Plus5 customer domains
Customcustom domains
  • demo environment allowed
  • localhost only in development
  • unknown domains blocked
  • per-domain usage metering

Incident response

Severity is defined before something goes wrong.

P0unsafe answer, data leak, abuse spike, wrong customer data
P1important hallucination, lead capture broken
P2UI issue or minor incorrect answer
P3copy/design issue

Data handling

Conversation retention and deletion need a visible workflow.

Conversation retention

Keep transcripts for analytics and quality review only as long as the customer policy allows.

Data deletion workflow

Customer requests should remove leads, transcripts, source snapshots, and agent settings from the active workspace.

Response flow

Every incident should create a diagnosis trail.

  1. pause agent if needed
  2. notify Sherry immediately
  3. preserve safe logs
  4. diagnose cause
  5. fix knowledge, guardrail, or config
  6. re-run QA
  7. republish
  8. send customer note if needed

What matters

Trust language stays evidence-backed.

Atithya describes practical controls clearly, without making HIPAA, SOC 2, ISO, or GDPR claims before the programs, terms, and reviews support them.

Visitor asksWhat keeps this from running on the wrong site or saying the wrong thing?
Atithya does

Shows approved sources, domain allowlists, rate limits, incident response, data handling, and instant pause.

Customer sees

Trust comes from practical controls and accurate non-claims, not inflated compliance language.

  • Source approval
  • Allowed domains
  • Rate limits
  • Pause-first incident flow
01

Approved source control

Customers approve what the agent can use before publish, and noisy content like blogs can be excluded by default.

02

Domain allowlist

Free supports one customer domain, Pro two, Plus five, and Custom as agreed. Demo and localhost are controlled separately.

03

Connection detail protection

Sensitive connection details stay outside the browser while visitors only see the approved agent experience.

04

Incident response

Pause the agent, preserve safe logs, diagnose the issue, fix configuration or knowledge, rerun QA, and republish.

Workflow

Launch controls

Security is treated as an operating control: approve sources, restrict domains, monitor incidents, and pause answers when needed.

  1. Source approval
  2. Domain allowlist
  3. Connection detail protection
  4. Tenant metering
  5. Rate limiting
  6. Usage caps
  7. Retention
  8. Deletion

Product principle

Evidence-backed trust language

No formal HIPAA, SOC 2, ISO, or GDPR claims until the product, process, legal terms, and audits support those statements.

Check my launch controls