Security
Give every visitor a real-time trust score, block suspicious activity automatically, and tune the rules — all from one page under Audience.
Where to find it
Security is a single entry in the left menu, under Audience → Security. It opens one page with four tabs across the top:
| Tab | What it covers |
|---|---|
| Overview | The numbers at a glance — blocked, low trust, allowed and average trust, plus the score distribution and the signals firing most often. |
| Visitors | Every visitor with their score, signals and status. Search, filter, and open a full security profile. |
| Blocked | Only the visitors Security is currently blocking, so you can allow them or clear the block. |
| Policy | The master switch, the two threshold lines, and which signals are switched on. |
Opening any of them needs the Security permission. Anyone who has it sees every visitor in the organisation — the list is not narrowed per brand or per chat widget.
Key concepts
Trust score
Every new, anonymous visitor starts in the neutral middle at 50. From there:
- Risk signals push the score down — a browser identifying itself as an attack tool, an attack-style URL, machine-paced activity, or a weak identity hint such as a disposable email address.
- Trust signals push the score up — an email address on file, an account that has been around a while, a visitor who actually wrote to you, or one who keeps coming back.
Weak risk signals fade after 30 days if the behaviour stops. The two attack-grade signals never fade, and trust a visitor has earned stays with them. Genuine search engine crawlers (Googlebot, Bingbot and the like) are filtered out before scoring and never appear here.
The two lines and three zones
You set two threshold lines that split the 0–100 scale into three colour-coded zones:
| Zone | Where the score sits | What happens |
|---|---|---|
| 🟢 Trusted | At or above the low-trust line | Chats normally, no friction |
| 🟡 Low trust | Between the two lines | Can still chat; simply flagged as low trust |
| 🔴 Blocked | Below the block line | Automatically blocked from chatting |
You can move both lines yourself, or pick a one-click protection level, on the Policy tab.
Trust band and team decisions
Security works on two layers:
- Trust band (passive) — derived straight from the score, this is awareness only. A visitor sits in one of three bands — Trusted, Low trust, or Blocked — based on where their score lands. A low-trust visitor is never pushed at anyone to "decide" on; they can still chat.
- Team decision (durable) — an optional, lasting choice your team makes that overrides the band:
- Allowed — a permanent exemption. This visitor is never auto-blocked again, even if their score later drops into the low-trust or blocked range.
- Blocked — this visitor is blocked, regardless of their score.
A visitor with no team decision simply follows their trust band.
What's inside
Overview
Key numbers at a glance — blocked, low-trust and allowed counts, trust distribution, top trust and risk signals, and recent low-trust visitors.
How it works
Scoring runs automatically in the background — no extra code or SDK changes are needed:
- The Yaplet widget collects the events it already gathers (page views, sessions, identity).
- Each visitor is evaluated against the built-in signals.
- Triggered signals raise or lower the visitor's trust score.
- If the score drops into the low-trust zone, the visitor is flagged as low trust (awareness only — no action required).
- If it drops below the block line, the visitor is automatically blocked — the chat widget locks in their browser straight away.
How long the records last
Yaplet deletes idle visitor records automatically, but a visitor carrying a security decision or a risk signal is never deleted, however long they sit idle. The history of a suspicious visitor does not quietly disappear.
That pruning does show in the numbers here. The four tiles and the trust distribution are counted from the visitor records still held, so a period far in the past can show fewer visitors than it did at the time.