Skip to main content

Security & privacy

The key is public by design​

The dk_… key ships in your page source — it's meant to be seen. It is not a secret: it identifies one embed and lets a visitor start a conversation with that one agent, billed to you. It does not grant access to your Digitorn account, your other agents, or anyone's data.

Restrict a key to your domains​

In the Embed tab you can pin a key to an allowlist of domains. A widget loaded on any other site is refused. Set this once your embed is live, so a copied key can't run your agent — and your bill — on a site that isn't yours.

Isolation​

  • The chat runs in an iframe on Digitorn's origin, so it can't read or alter your page, and your page can't read the conversation.
  • Browser storage is partitioned: a visitor's conversation on your site never reaches their own Digitorn history, or another site's embed of the same agent.
  • A full theme saved on a key applies to that embed only — never to another embed, another agent, or Digitorn.

Each visitor is their own user​

A visitor never borrows your account. Each one gets their own user of your agent, limited to chatting with that one agent: they can't reach your other agents, your settings, or another visitor's conversations and accounts. You can read their conversations and suspend them from the Users tab. See Visitors & verified users.

Visitor context is self-declared​

Anything you pass with setContext / identify is declared by your site. It's ideal for personalisation and for telling the agent which page the visitor is on. It is not verified identity: it never merges two visitors or opens anyone's accounts, and the agent is instructed not to act on it for sensitive or account-specific requests without its own verification. Don't put secrets (passwords, API keys) in it.

To prove who a user is, sign a token on your server with your private key and give us only the public key — see verified users.

What reaches the agent​

A conversation, and the context you choose to pass, reach the agent (and its LLM) to produce replies — the same as any chat with that agent. Send only what you're comfortable sharing with it, and keep credentials out of the context.