Skip to content

Clear boundaries around your websites and workspace.

Understand the controls that are implemented, the information the assistant uses, and the checks your team should make before rollout.

Access follows the workspace and project.

Workspaces separate organisations, while project-scoped memberships limit access within an agency. Management actions check the acting user’s permissions on the server.

Staff administration is restricted to staff accounts. Account settings let a user change their password and revoke sessions; password changes end other sessions. Passwords are stored as salted scrypt hashes.

Live chat follows site access and assignment.

A site administrator enables live chat and selects active workspace members who can access that website. Client viewers cannot configure or operate live chat, and a specialist cannot claim a conversation from an unassigned site.

The first eligible specialist claims the chat atomically. Only that specialist can reply or end it while they remain active; takeover becomes available after the owner stops reporting presence for the defined inactivity window.

Reading a site has limits.

A full website crawl requires ownership verification. The fetch layer checks destinations to prevent access to private network addresses, follows robots.txt, and applies crawl and usage limits.

Source exclusions and saved answers let your team control what informs a reply. Instruction-like text in crawled content is filtered, and the response guard checks unsupported currency and percentage claims. These controls reduce risk; generated answers still need evaluation.

Ask Sairo follows the same access boundaries.

Ask Sairo checks workspace membership, project access and website scope for each operation. Its conversation history belongs to the signed-in user; applied changes affect the shared records that user is permitted to edit. Visitor text and website content do not grant permissions.

Supported changes record the proposed value and prior state. Applying or undoing a change checks the current record and rejects a stale update. Explicit direct corrections can be saved automatically only when the dashboard setting and the request qualify; other proposals have review controls.

The tool set does not expose arbitrary database queries, billing, team administration, credentials or outbound customer messaging. Ask Sairo’s tools are fixed and are not the same thing as the actions a website can configure for its visitor assistant; those run on the visitor side, against endpoints that website’s own team registers.

Choose and revoke external application access.

Sairo’s public MCP endpoint uses OAuth authorisation with PKCE. Sign-in lets you select the workspace, website access and whether to allow changes. Read access is the default. The service checks the connection and your current team permissions on each request.

Access tokens are short-lived and stored as hashes. Refresh tokens rotate, and the connection expires after 30 days unless you reconnect. Disconnecting, changing a password or resetting it revokes the connection. Ordinary website sign-out leaves separately authorised applications connected.

The service records prepared and applied changes, but an external application controls its own confirmation interface. Choose read-only access when it should not make updates. Disconnecting stops future access; it cannot retrieve information already shared with that application.

Provider credentials stay on the server.

The installed widget carries a public site key, not your AI provider credential. The production service uses HTTPS, and the configured OpenRouter key is supplied to server processes through deployment settings.

Messages and relevant website excerpts may be sent to the configured AI provider to produce replies and embeddings. Review the data flow and provider terms before using the assistant for a sensitive workflow.

An action reaches only where you point it.

A website can let its assistant call a system you already run. Sairo accepts only HTTPS addresses that resolve to public hosts, so an action cannot be aimed at a private network or a cloud metadata service, and that check is repeated when the call is made rather than only when it is saved. A site may hold up to ten actions and the assistant may run at most two in a single reply.

What an action returns is treated as evidence, not as instruction: it enters the answer the same way a page from your website does, and the assistant still refuses to state anything the evidence does not support. Every call is recorded with the address, what was sent and what came back, for your own team to read.

Files are stored, not rendered.

A photo or PDF sent in a conversation is identified by reading its own bytes rather than trusting its name or its stated type. SVG is refused because it can carry script. Every attachment is served as a download under a restrictive content policy, so nothing a visitor uploads is ever executed or displayed as part of a page.

Uploaded reference documents become indexed knowledge and are addressed by an internal identifier rather than a web address. A citation therefore never links a visitor to a page that does not exist.

API keys are hashed and scoped.

An API key is stored as a hash with a short visible prefix, so you can recognise a key in a list but nobody, including Sairo, can read it back. Read and write access are separate scopes, a key is limited to the workspace that issued it, and revoking one takes effect immediately.

A verified custom domain serves that website’s help centre and nothing else. The workspace and the API stay on sairo.app, so a domain you point at Sairo cannot become a second entrance to an account.

Refuse a visitor who is abusing your team.

A live chat transcript is written partly by anonymous visitors. From the live chat desk or the inbox, on the web or in the desktop app, a specialist can block that visitor and can report the conversation to Sairo. Blocking asks for a reason, ends any live chat still open with them, and takes effect on the assistant, live chat, dictation and the realtime connection.

A block records the token the widget keeps in that browser and a hash of the network address the conversation came from. Someone who clears their browser data or moves to another network can return, so treat it as a deterrent and an operator control rather than an identity check. Address blocks expire after 30 days because addresses are reassigned and shared. Active blocks are listed under a website’s live chat settings and can be lifted there.

Reporting is separate and never blocks on its own. It sends the conversation to the Sairo team for content your own team should not have to resolve. Anyone can also report abuse through the contact form.

Bring specific requirements to the review.

This page describes implemented product controls. It does not claim SOC 2 certification, a particular data-residency region, an uptime guarantee, or an independent security audit.

If your procurement process requires a security questionnaire, retention agreement, or contractual commitment, contact Sairo before sending that category of information to the service.

See what your website can answer.

Try a sample, review the result, and decide what comes next.