Chatzuri
Pricing
Guides
Guides
Introduction
  1. 1Getting Started
  2. 2Your Agent
    • Create an agent
    • AI configuration
    • Personality and presentation
    • Customise the chat widget
    • Test in the Playground
    • Voice, video, images, and files
    • How memory works
    • Multi-agent orchestration
    • Performance and cost controls
    • Security and access control
    • Compliance and guardrails
    • Improve response quality
  3. 3Knowledge & Sources
  4. 4Agent actions & Tools
  5. 5Agent Tasks
  6. 6WorkflowsBeta
  7. 7Channels
  8. 8Customers & Conversations
  9. 9Run Your Team
  10. 10Developer Tools
Developer reference →Showcase →
Guides2. Your AgentSecurity and access control
Chapter 2 · Your Agent

Security and access control

Restrict embedding to specific domains and rate-limit chat traffic per visitor.

4 min read

The Security panel controls who can talk to your agent and how often. Two settings live here: an allowlist of domains that can embed the widget, and a per-visitor rate limit.

Find these settings under Settings → Security on any agent. The agent's public/private toggle lives under General Settings.

Allowed domains

By default a public agent can be embedded anywhere on the open internet. Add domains to the Allowed Domains field to restrict where the widget will load:

  • One domain per line — for example mysite.com and app.mysite.com.
  • The check is exact-hostname. Subdomains are not implied — list each subdomain explicitly if you need it.
  • Leave empty to allow every domain.

When a visitor loads the embed from a domain that isn't on the list, the widget refuses to render and shows an "unauthorised" message.

Heads up
Domain restrictions only apply when the agent is public. They prevent casual copy-paste embedding of your widget on someone else's site, not determined abuse. For stronger guarantees combine with rate limiting and a custom domain.

Rate limiting

The Rate Limiting field caps how many messages a single visitor (by IP) can send within a 60-second window. When the cap is hit, the next message is refused with the message you set in Rate Limit Message.

Typical values:

  • 0 — no per-visitor limit (the team plan's overall limit still applies).
  • 10–30 — sensible defaults for an interactive support widget.
  • 3–5 — strict; useful when the agent triggers expensive tools on every message.

What else protects an agent

Other panels include security-adjacent settings. Pair Security with:

  • Performance — set daily and monthly token caps so a runaway visitor can't drain the budget.
  • Compliance — turn on PII redaction so logs never store sensitive details, and audit logging so security events are traceable.
  • Custom domains — serve the widget from your own subdomain rather than chatzuri.com.
Previous · Your AgentPerformance and cost controlsNext · Your AgentCompliance and guardrails
Chatzuri

AI-powered agents are transforming customer interactions by providing instant, intelligent responses around the clock. They help businesses reduce operational costs, improve response times, and scale support without compromising quality. These agents understand natural language, learn from conversations, and integrate with existing systems to offer personalized experiences that enhance customer satisfaction and loyalty.

Chatzuri

AI-powered agents are transforming customer interactions by providing instant, intelligent responses around the clock. They help businesses reduce operational costs, improve response times, and scale support without compromising quality. These agents understand natural language, learn from conversations, and integrate with existing systems to offer personalized experiences that enhance customer satisfaction and loyalty.

Product

  • Pricing
  • Security
  • Affiliates

Resources

  • API
  • Guides
  • Blog
  • Help

Company

  • About us
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA

About

  • Teams
  • Singapore, Nairobi

© 2026 Chatzuri. All rights reserved.

Chatzuri uses AI and can make mistakes.

Terms of ServicePrivacy PolicyCookie PolicyChatzuri