Security

A small widget with clear security boundaries.

Embedding third-party software deserves care. Feedback Bubble limits where each site key works, isolates its interface and validates every submission on the server.

Isolated widget rendering

The visible feedback form runs inside a transparent iframe. Host-page styles cannot silently rewrite the form, and widget styles do not leak into the customer website.

Approved website origins

A public site key only returns usable configuration when it is requested from an origin approved for that bubble.

Short-lived widget sessions

Successful configuration requests issue a temporary submission session. Expired or invalid sessions are rejected rather than trusted indefinitely.

Strict input validation

Categories, message length and page-context fields are restricted on the server. Unsupported fields are not accepted simply because a browser sends them.

Plain text by default

Customer messages are displayed as text, not interpreted as HTML. Script tags and markup submitted in feedback are not executed in the inbox.

Rate and entitlement checks

Submission limits reduce automated abuse, while inactive or unsubscribed bubbles are prevented from loading as active widgets.

Data minimisation

Collect the context you need, not the page around it.

The standard widget collects the customer’s chosen feedback type and message together with the current page title, path and URL. It does not scrape page content or automatically capture values entered into forms.

Report a security concern

Please send a clear description and reproduction steps privately. Do not include customer data that is not required to explain the issue.

hello@getfeedbackbubble.com

Secure installation starts with the correct origin.

Create a separate bubble and site key for each website rather than sharing one configuration everywhere.

Create your bubble