Tutorials

Securing and Customizing Your Widget for Enterprise Standards

PicoBot Team
Securing and Customizing Your Widget for Enterprise Standards

When you deploy an AI agent on your website, it becomes the face of your company. It is often the very first interaction a potential customer has with your brand.

Therefore, a generic, unbranded chatbot is simply unacceptable for modern businesses. Furthermore, as your traffic scales, you need robust security measures to ensure your AI isn’t hijacked, embedded on unauthorized sites, or abused by malicious actors.

Here is a deep dive into PicoBot’s Web Widget settings and how to configure them for enterprise-grade deployment.

1. Pixel-Perfect Brand Customization

Your chatbot should feel like a native extension of your website, not a third-party plugin that was hastily bolted on.

Navigate to Web Widget > Customization in your dashboard. Here, you should:

  • Match Your Hex Codes: Don’t settle for “close enough.” Input the exact primary and secondary Hex color codes from your brand guidelines.
  • Custom Avatars: Replace the default robot icon with your company logo, or better yet, a high-quality headshot of a real support team member (which increases engagement rates).
  • Remove Branding: Upgraded plans allow you to remove the “Powered by PicoBot” watermark, ensuring a fully white-labeled experience for your users.

2. Setting the Stage with Initial Messages

The first message your bot sends dictates the flow of the entire conversation. If it just says “Hi,” the user won’t know what it’s capable of.

Configure a strong Welcome Message that sets expectations:

  • “Hi there! I’m the ACME Corp AI assistant. I can help you track an order, process a return, or answer questions about our pricing. How can I help you today?”

You can also configure Suggested Questions (canned responses) that appear as clickable chips above the text input. This drastically reduces friction for mobile users and guides them toward your most common support flows.

3. Locking Down Security: Whitelisting Domains

One of the most critical security settings is found under Web Widget > Whitelist Domains.

Because deploying PicoBot is as simple as copying and pasting a JavaScript snippet, a malicious actor could theoretically copy your snippet and paste it onto their website. Your AI would then start answering questions on their domain, potentially causing brand confusion or consuming your AI usage credits.

The Fix: Simply add your specific domains (e.g., www.yourcompany.com and app.yourcompany.com) to the Whitelist. Once enabled, PicoBot will instantly block the widget from rendering on any domain that isn’t explicitly approved.

4. Geographic Filtering (Geo-Blocking)

If you only sell products in North America and Europe, you don’t want to burn through AI credits answering thousands of spam queries originating from regions you don’t service.

Under Web Widget > Geo-Blocking, you can explicitly block or allow traffic from specific countries. If a user from a blocked region visits your site, the widget will remain hidden, protecting your resources and keeping your analytics clean.

5. Transparency and Trust

Enterprise trust requires transparency. In the Web Widget > Display AI Sources setting, you can choose whether or not the bot shows its work.

When enabled, the bot will append small citation links (e.g., [1], [2]) at the end of its answers. When clicked, these link directly to the specific page in your Knowledge Base or website where the bot got its information. To learn how to properly construct your Knowledge Base for these citations, read our guide on Mastering the Knowledge Base. This proves to the user that the bot isn’t hallucinating, and allows them to read further if they choose.

By taking 10 minutes to configure these advanced settings, you transform a simple chat widget into a secure, branded, enterprise-grade AI agent.

Secure and customize your widget in the dashboard today.


Ready to build your AI agent?

Join developers using PicoBot to deploy powerful AI agents in minutes. No credit card required.