Guide

Answering Security Questions From Customers

5 minute read · Updated August 10, 2026

Being assessed is different from assessing

Plenty has been written about how to evaluate a chat vendor. Rather less covers the other side of that conversation, which is what happens when a prospect asks you how the chat on your website handles their information — sometimes casually in the chat itself, sometimes as a formal questionnaire before a contract. Support and sales people field these questions constantly and are rarely given anything accurate to say, which is how overclaiming starts.

The stakes are higher than they look. An answer given in chat is written down, timestamped and attributable, and a confident claim that turns out to be untrue is materially worse than an honest “I will find out.” This is one of the few areas where the cautious answer is also the commercially better one.

Work out what is actually true first

You cannot answer well from instinct. Before anyone is asked, establish the small set of facts that cover most questions: what your chat collects, where that data is stored, how long you keep it, who on your side can see it, whether AI is involved in generating replies, and which third parties are in the picture. That is six answers, and most security questions are a rephrasing of one of them.

Write them down in plain language in a place your team can find in the middle of a conversation. The failure mode is not that people lie — it is that they are asked something reasonable, do not know, and produce a plausible-sounding sentence under time pressure.

Never claim a certification you do not hold

This is the single most important rule and the easiest one to break by accident, because the pressure is real. A prospect asks whether you are compliant with some framework, the deal is worth having, and there is a strong pull toward an answer that sounds like yes. The correct behaviour is to state exactly what is true: what you actually do, and whether you hold a formal certification, which are two entirely separate claims.

Good practice and certification are not the same thing, and conflating them is what gets companies into trouble. You can describe your controls honestly and in detail without asserting an audit you have not had. Buyers who need the certification will ask directly and will verify; buyers who do not will usually be satisfied by a clear description of what you actually do. Neither group is well served by ambiguity, and one of them is capable of ending a contract over it.

Separate your own claims from your vendor’s

Chat introduces a third party into your website by design, and questions about it are really questions about a chain. What the vendor does, what you do with what the vendor gives you, and what your agents do in practice are three different things, and answering as though they are one thing is how inaccurate statements get made in good faith.

Attribute clearly. Saying that your chat provider encrypts data in transit is a statement about them; saying that your team never asks for card details in chat is a statement about you; saying that transcripts are deleted after a set period is a statement about a policy you must actually have implemented. Keeping the subject of each sentence straight is most of the accuracy.

Know which questions leave the chat window

Some questions should not be answered by whoever happens to be on shift. Anything involving a contract, a legal commitment, a data processing agreement, or a description of your internal security architecture belongs with a named person, not with the agent who picked up the conversation. Give the team an explicit list and a route, so the answer is a confident handoff rather than an improvised attempt.

Handled well, this reads as competence rather than evasion. “That is a question for the person who owns our data agreements, let me put you in touch” is a stronger answer to a serious buyer than a fast approximation from someone guessing, and it takes the pressure off the agent entirely.

Be careful about describing your own defences in detail

There is a distinction between transparency about how customer data is handled, which is right, and volunteering the specifics of your internal controls to an anonymous person in a chat window, which is not. A stranger asking exactly which systems hold what, who has administrative access and how agents verify identity may be doing diligence, and may equally be doing reconnaissance for a social engineering attempt later in the week.

The resolution is not secrecy but routing: policy-level answers are fine in chat, architectural detail goes through a channel where you know who you are talking to. Genuine enterprise diligence always has an identified buyer attached and is happy to move to email or a call.

Keep the answers current, or they become false

A security answer sheet ages badly. Retention periods change, tools get added, an AI feature is switched on, a vendor is replaced — and the document keeps confidently saying what used to be true while your team keeps quoting it. Attach it to something that already recurs, a quarterly review or the moment any new tool touches chat data, and check the claims still hold.

Pay particular attention when you turn something on. Adding AI-generated replies changes the honest answer to “is a human reading this?” and adding a new integration changes the answer to “who else receives this data?” Those are exactly the questions buyers ask, and exactly the answers most likely to go stale unnoticed.

How MyLiveChat fits

Several of the facts you will need are MyLiveChat settings rather than opinions, which makes them easy to state accurately: chat runs over an encrypted connection, transcripts are retained and searchable in the dashboard, agent access is per-account with admin or agent roles, and there is a self-hosted option for organisations whose requirements mean the data must stay on infrastructure they control. That last distinction is the one to state precisely rather than loosely, because self-hosted and managed cloud are genuinely different answers to a buyer’s question about where data lives. Describe what is configured, point to documentation for the rest, and route contractual questions to a person.

The hardest of these questions is usually about staff access rather than encryption, because it has no reassuring one-word answer. Who can open your dashboard when you ask for help gives you the specifics to quote when a customer asks who can see their conversations.

Put it into practice

MyLiveChat is free forever for one agent, with unlimited chats and the embed code ready in about a minute.

Free forever for 1 agent

Give every visitor an instant way to reach you.

Launch live chat, connect your knowledge base, and add AI answers when you are ready. No credit card, no trial clock.