Security

Give every visitor a real-time trust score, block suspicious activity automatically, and tune the rules — all from one page under Audience.

Where to find it

Security is a single entry in the left menu, under Audience → Security. It opens one page with four tabs across the top:

TabWhat it covers
OverviewThe numbers at a glance — blocked, low trust, allowed and average trust, plus the score distribution and the signals firing most often.
VisitorsEvery visitor with their score, signals and status. Search, filter, and open a full security profile.
BlockedOnly the visitors Security is currently blocking, so you can allow them or clear the block.
PolicyThe master switch, the two threshold lines, and which signals are switched on.

Opening any of them needs the Security permission. Anyone who has it sees every visitor in the organisation — the list is not narrowed per brand or per chat widget.

Security is included on the Growth plan. If your plan doesn't include it, the Security entry doesn't appear in your menu and no scoring runs. Blocking a visitor by hand from a conversation in the inbox is a separate mechanism — it works on every plan, and it is tracked separately from Security's automatic block. It is still visible on the visitor's security profile here, where it can also be lifted.

Key concepts

Trust score

Every new, anonymous visitor starts in the neutral middle at 50. From there:

  • Risk signals push the score down — a browser identifying itself as an attack tool, an attack-style URL, machine-paced activity, or a weak identity hint such as a disposable email address.
  • Trust signals push the score up — an email address on file, an account that has been around a while, a visitor who actually wrote to you, or one who keeps coming back.

Weak risk signals fade after 30 days if the behaviour stops. The two attack-grade signals never fade, and trust a visitor has earned stays with them. Genuine search engine crawlers (Googlebot, Bingbot and the like) are filtered out before scoring and never appear here.

The two lines and three zones

You set two threshold lines that split the 0–100 scale into three colour-coded zones:

ZoneWhere the score sitsWhat happens
🟢 TrustedAt or above the low-trust lineChats normally, no friction
🟡 Low trustBetween the two linesCan still chat; simply flagged as low trust
🔴 BlockedBelow the block lineAutomatically blocked from chatting

You can move both lines yourself, or pick a one-click protection level, on the Policy tab.

Trust band and team decisions

Security works on two layers:

  • Trust band (passive) — derived straight from the score, this is awareness only. A visitor sits in one of three bands — Trusted, Low trust, or Blocked — based on where their score lands. A low-trust visitor is never pushed at anyone to "decide" on; they can still chat.
  • Team decision (durable) — an optional, lasting choice your team makes that overrides the band:
    • Allowed — a permanent exemption. This visitor is never auto-blocked again, even if their score later drops into the low-trust or blocked range.
    • Blocked — this visitor is blocked, regardless of their score.

A visitor with no team decision simply follows their trust band.

What's inside

Overview

Key numbers at a glance — blocked, low-trust and allowed counts, trust distribution, top trust and risk signals, and recent low-trust visitors.

Visitors

Every visitor with their trust score, trust band, and risk signals. Search, filter, and open a full security profile.

Blocked

Visitors blocked by Security — review and Allow or Clear them in one place.

Policy

Choose a protection level, move the low-trust and block lines, and turn individual signals on or off.

How it works

Scoring runs automatically in the background — no extra code or SDK changes are needed:

  1. The Yaplet widget collects the events it already gathers (page views, sessions, identity).
  2. Each visitor is evaluated against the built-in signals.
  3. Triggered signals raise or lower the visitor's trust score.
  4. If the score drops into the low-trust zone, the visitor is flagged as low trust (awareness only — no action required).
  5. If it drops below the block line, the visitor is automatically blocked — the chat widget locks in their browser straight away.
A blocked visitor stays blocked until either their score climbs back above the block line (the automatic block lifts and they return to the low-trust zone) or your team clears the status. Manual bans and automatic blocks are tracked separately, so one can't accidentally undo the other.

How long the records last

Yaplet deletes idle visitor records automatically, but a visitor carrying a security decision or a risk signal is never deleted, however long they sit idle. The history of a suspicious visitor does not quietly disappear.

That pruning does show in the numbers here. The four tiles and the trust distribution are counted from the visitor records still held, so a period far in the past can show fewer visitors than it did at the time.