{"generatedAt":"2026-08-10T16:42:38.328Z","source":"ismscopilot-marketing","contract":"v1","product":"isms-copilot-embed","status":"live","canonicalHumanPage":"https://www.ismscopilot.com/products/embed","docsPage":"https://docs.ismscopilot.com/docs/embed","consoleUrl":"https://platform.ismscopilot.com/embed","loaderUrl":"https://embed.ismscopilot.com/loader.js","widgetOrigin":"https://embed.ismscopilot.com","publicAuth":"pk_live_… public key + exact-origin domain allowlist; short-lived server-minted public session.","identifiedAuth":"Partner-signed HS256 JWT (kid-based), 24-hour maximum lifetime enforced server-side.","publicTranscriptRetention":"Sliding ~30-day expiry after last activity, then daily purge (asynchronous deletion; effectively 30-31 days).","identifiedTranscriptRetention":"No automatic TTL; kept until partner deletion or offboarding. DPA / manual erasure path applies.","usageMetadataRetention":"Usage and billing metadata (model, tokens, credits, timestamps) retained separately long-term for metering, fraud prevention, and statutory accounting.","freeTier":"100 AI replies per calendar month, hard-stop, no card, one assistant. Public replies debit the partner's total allowance; not an additional pool.","keyPlanes":"Embed uses pk_live_… or partner JWT; Model API uses sk-isms-…; Account MCP uses pat-isms-…. Three separate credential planes.","not":["waitlist (console is live and self-serve)","full white-label chat (Powered by footer on Free/Entry/Starter; hidden on Growth+ active/trialing; AI transparency and Privacy always on)","visitor-side history sidebar or reload resume (multi-turn while open; console inbox for partners when history is enabled)"],"note":"Product is live. Live prices are shown only in the console upgrade block; this feed carries no currency amounts.","markdown":"# ISMS Copilot Embed / Assistants (product truth)\n\nMachine-readable product summary for agents. Human product page: https://www.ismscopilot.com/products/embed  \nAuthoritative how-to: https://docs.ismscopilot.com/docs/embed  \nConsole (playground, keys, install snippet): https://platform.ismscopilot.com/embed\n\n## Status\n\n**Live.** Self-serve Assistants console at platform.ismscopilot.com/embed: playground, brandable assistant name, install snippet, domain allowlisting, free plus paid reply tiers. Not a waitlist.\n\n## Install\n\n```html\n<script src=\"https://embed.ismscopilot.com/loader.js\"></script>\n<script>\n  IsmsCopilotEmbed.init({\n    partnerId: \"<your-partner-id>\",\n    publicKey: \"<public-key-from-console>\",\n  });\n</script>\n```\n\nWidget origin: `https://embed.ismscopilot.com`  \nAlways copy the console-generated snippet; if docs and console disagree, the console wins. Header name and model self-ID come from the server (Assistant name in the console), not a client `title` field.\n\n## Auth planes\n\n| Path | Mechanism |\n| --- | --- |\n| Public install | `pk_live_…` public key + exact-origin domain allowlist; short-lived server-minted public session |\n| Identified install (advanced) | Partner-signed HS256 JWT (`token` field), kid-based, **24-hour maximum lifetime** enforced server-side |\n\nKey-plane contrast (do not mix up):\n\n| Product | Credential |\n| --- | --- |\n| Embed / Assistants | `pk_live_…` public key or partner JWT |\n| Model API | `sk-isms-…` (https://www.ismscopilot.com/api/public/api/v1) |\n| Account MCP (Agents) | `pat-isms-…` (https://www.ismscopilot.com/api/public/agents/v1) |\n\n## Transcript retention (dual path)\n\n| Install path | Retention |\n| --- | --- |\n| Public key (anonymous visitors) | Sliding ~30-day expiry after last activity, then a daily purge deletes the thread; deletion is asynchronous, so effectively 30-31 days |\n| Identified JWT | **No automatic TTL.** Kept until the partner deletes them or completes offboarding; DPA and manual erasure path applies |\n\nUsage and billing metadata (model, tokens, credits, timestamps) is retained separately long-term for metering, fraud prevention, and statutory accounting. It is not covered by the transcript purge.\n\nLegal package: https://trust.ismscopilot.com/embed/terms, https://trust.ismscopilot.com/embed/dpa, https://trust.ismscopilot.com/embed/subprocessors\n\n## Free tier\n\n- **100 AI replies per calendar month**, hard-stop at exhaustion, no card required, one assistant.\n- Public visitor replies debit the partner's **total** allowance as well as the public sub-budget; the 100 public replies are **not** an additional pool on top of a paid plan.\n- Paid tiers are EUR monthly reply pools (Entry, Starter, Growth, Scale). Live prices and allowances are shown only at the console upgrade block; this feed intentionally carries no currency amounts.\n- EU processing (Advanced Data Protection) is a Growth+ option, not on Free.\n\n## What it is not (honest limits)\n\n- Not a waitlist: the console is live and self-serve.\n- Not a full white-label chat product. **Powered by ISMS Copilot** footer: on for Free/Entry/Starter; hidden automatically on Growth/Scale/Enterprise (active or trialing). AI transparency and Privacy disclosure stay on for every tier.\n- No visitor-side conversation history sidebar or reload resume: multi-turn works while the widget is open; a reload starts a fresh widget conversation. Partners review transcripts in the console inbox when history is enabled.\n- Not the Model API (`sk-isms-…`), not Account MCP (`pat-isms-…`), not heyGRC, not the chat subscription.\n\n## Links\n\n- Create your first website assistant: https://docs.ismscopilot.com/docs/embed/create-website-assistant\n- Install the snippet: https://docs.ismscopilot.com/docs/embed/install-snippet\n- Conversations and history: https://docs.ismscopilot.com/docs/embed/conversations-and-history\n- Plans and usage: https://docs.ismscopilot.com/docs/embed/plans-and-usage\n- EU processing: https://docs.ismscopilot.com/docs/embed/eu-processing\n- Platform changelog (JSON): https://www.ismscopilot.com/api/public/platform-changelog/v1\n- Live dogfood example: https://betterisms.co\n","byteLength":4156}