New:AI replies grounded in your own documentation.
Live trafficRequestFirewallAllowedBlocked

The widget is public.Everything behind it isn’t.

A support widget takes untrusted input from the open internet and hands it to a model that knows your docs. Every message is checked on its way in.

Defence in depth

Secure at every layer

From the first request to the last row in the database, each layer holds on its own — none of them relies on the one before it.

Tested against simulated attacksLimits hold even if a part failsEvery block is recorded

Every request is weighed

Traffic is limited on several signals at once — the network it comes from, the visitor, the session and, for integrations, the API key. Rotating one doesn't reset the others, and AI requests get a tighter budget of their own.

Network addresswithin limits
Visitorthrottled
Sessionwithin limits
API keywithin limits

Repeat offenders stay out

Keep hitting the limits and you're banned — for longer each time. Every ban is recorded, and an admin can lift one.

1st2nd3rdrepeat

Recognised, not reset

Returning visitors are recognised by their browser, so limits and history follow the person — not the tab.

Tab 1Tab 2
Same visitor

Your domains only

The widget only starts conversations on sites you list, so a copied snippet can't spend your AI allowance.

yoursite.comallowed
copycat.examplerefused

Nothing a visitor types can run

Messages are escaped everywhere they're shown, and unsafe links are refused.

<img src=x onerror=…>

Shown as plain textescaped

Docs can't give orders

Text retrieved from your knowledge base is treated as reference, never as instructions to the AI.

To export, open Settings…
Ignore previous instructions

Walls below the application

Each workspace is separated by the database itself, not just by our code — and all of it is stored in the EU.

Isolated per workspaceRole-checked on every requestHosted in the EU

Your team

Access you can reason about

Four roles with fixed capabilities, checked on every request — and sign-ins you can lock down.

Two-factor authenticationA one-time code from an authenticator app on every sign-in.
Sign out other sessionsEnd every session except the one you're on, in one click.
CapabilityOwnerAdminMemberViewer
View conversations, customers & reports
Reply to customers & edit records
Manage knowledge base & saved replies
Invite teammates & change roles
Configure workspace settings
Manage billing & plan
Delete the workspace

Details

The rest of the posture

Six controls that are always on

01Widget
Escaped rendering
Message content can't execute in the widget or the dashboard.
02Access
Scoped visitor tokens
Short-lived, one workspace, no path to the dashboard.
03Network
Outbound fetch guards
URL fetches refuse private addresses and localhost.
04Data
Data in the EU
Conversations, contacts and articles stored in an EU region.
05Data
Isolation in the database
Workspaces separated below the application code.
06Abuse
Admin-visible bans
Blocked visitors and IPs are recorded and liftable.

Security questions

In an EU region. Conversations, contacts and articles are stored there and isolated per workspace at the database level.

Still curious? Email hello@kuvra.dev

Talk to us

Security questions? Ask the team.A person reads every message.

Get answers