Security
A public widget, a protected budget
Anything a browser sends can be imitated by a script. So instead of trusting one signal, AskMerra stacks six layers that make abuse expensive, visible and financially bounded.
Domain lock
Your site key works only on the domains you list. Requests from any other site are rejected, and browsers there don’t even get CORS permission to call the API.
Browser screening
Requests that don’t look like a real browser (command-line tools, scripting libraries, missing fetch metadata) are filtered before they reach the AI.
Proof-of-work sessions
Before chatting, the widget solves a small cryptographic puzzle (a fraction of a second for a real visitor) and receives a signed, short-lived session bound to your shop, the visitor and the page. Thousands of fake sessions cost thousands of puzzles.
Rate limits
Per visitor, per IP address (stored only as a hash) and per shop. Rotating visitor ids does not reset them.
Spend circuit breakers
If AI spend or new conversations spike, your shop enters protection mode: free answers (greetings, FAQ, cached answers) keep working, everything else gets a polite “busy” message with the contact form. You also get one email.
Spending caps
Your included usage and an optional monthly spending cap stop AI answers at a hard ceiling, whatever happens upstream.
Default rate limits
| Messages per visitor | 20 / minute |
| Messages per IP address | 60 / minute |
| Messages per shop | 600 / minute |
| New conversations per visitor | 30 / day |
| New conversations per IP address | 60 / day |
| Widget sessions per IP address | 60 / hour |
Spend circuit breakers
| AI cost per shop | $5 / hour | Protection mode for 60 minutes |
| AI cost per shop | $25 / day | Protection mode until midnight UTC |
| New conversations per shop | 500 / hour | Protection mode for 60 minutes |
A platform-wide breaker protects every shop at once. You can resume the assistant from the dashboard at any time.
Data protection
Infrastructure
Hosted in the EU. Encrypted in transit (TLS). Tenant isolation is enforced on every query and covered by automated tests.
Credentials
Passwords hashed with argon2id, optional two-factor login, API keys stored only as SHA-256 hashes and shown once, httpOnly session cookies with CSRF protection.
Shopper privacy
Shoppers get a random id, never a name or email unless you turn on identification. Raw IP addresses are never stored; country comes from CDN headers. Conversation retention is configurable per shop.
Responsible disclosure
Found a vulnerability? Email [email protected] with details and steps to reproduce. We respond within two business days and never take legal action against good-faith research. Technical details are in the security documentation.