Skip to content
Shahid Malla

AI chatbot development

AI Chatbot Developer for Websites, Support and WHMCS

I'm an AI chatbot developer who builds custom chatbots for business websites and support desks. Each one is built to answer from your own documents, to say it does not know when the documents are silent, and to pass the conversation to a person with a summary. It suits owners and support leads who want fewer repeat questions.

By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated

What is a custom AI chatbot made of?

A custom AI chatbot is five parts working together: a language model, your own documents, written rules, a hand-off to a person and logs. The model is the smallest part of the work.

  1. A language model through an API. OpenAI or Anthropic models write the replies. The model holds no knowledge of your business; it phrases an answer from what it is given.
  2. Your documents, fetched at question time. I cut your pages and policies into chunks split at headings and turn each into an embedding, a list of numbers that captures its meaning, kept in a vector store. For each question, the closest chunks are sent to the model with it.
  3. Rules. A system prompt sets the job, tone and topic limits. Rules that matter are also enforced in code, because a prompt can be argued with.
  4. A hand-off. The visitor can reach a person, who sees a short summary of what was said.
  5. Logs. Each conversation is stored with the chunks fetched and the cost, so you can see why the bot said what it said.

Around these sit details visitors feel: replies streamed word by word, retries with backoff on rate-limit errors, and a polite fallback if the provider is down.

What can an AI chatbot do, and what can't it do?

It can answer questions that your documents already answer and route everything else to a person. It cannot be promised to be right every time.

A language model writes fluent text whether or not it is true. So the bot is built to answer only from the chunks it fetched, shows the page each answer came from, and is tested to say "I don't know" and offer a person when those chunks do not answer. It changes nothing in your account or billing systems; the only write is the hand-off ticket or email. Changing things is an agent's job.

FAQ page, chatbot or AI agent: which do you need?

Choose by what the visitor needs done: find an answer, ask in their own words, or get something changed.

OptionSuitsWhat it costs to runMain risk
FAQ pageA dozen stable questions.Hosting and someone keeping it current.Visitors do not find the answer.
ChatbotMany questions in many wordings, answered from existing documents.Model tokens on every message, plus hosting for the vector store.A wrong or off-topic answer. Sources, "I don't know" and testing reduce it.
AI agentTasks that change something, such as updating an order.The same, plus more model calls per task.A wrong action. Narrow permissions and human approval reduce it.

If a good FAQ page would do, I will say so. AI chatbot vs AI agent compares the trade-offs; AI agent development covers bots that act.

Where is an AI chatbot for a website or support desk used?

Four deployments are typical.

  • Pre-sales questions on a website. The bot answers from your published pages and passes a ready visitor to sales. It is told not to quote prices or discounts that are not on your published pages.
  • An AI customer support chatbot on a knowledge base. It answers repeat questions with a link to the article and opens a ticket when the article does not help.
  • Hosting and WHMCS support. It reads the logged-in client's service context, read-only.
  • An internal knowledge assistant. Staff ask about runbooks and policies behind a login.

Can a WHMCS chatbot see my clients' data?

A WHMCS chatbot can read a client's services, invoices and ticket history through the WHMCS API, but only for the logged-in client and only through a read-only credential. The identity comes from the client area session, never from what is typed, so entering someone else's email gets nothing. The credential is a dedicated API role limited to the commands needed, so a badly worded answer cannot change an invoice or a service.

Disclosure: I founded WHMCSPilot.com, which sells WHMCS modules and themes, so I have a commercial interest here. My article on WHMCS AI chatbots sets out what such a bot needs to do, names no other product and does not list WHMCSPilot's features, and neither does this page. For the WHMCS API side, see WHMCS API integration and automation.

How is a chatbot build run?

A build runs in seven steps, and the test on your real questions comes before launch.

  1. Collect 50 to 100 real questions from tickets, chats and sales emails, with the customers' own spelling.
  2. Clean the sources. Outdated pages and two versions of one policy cause wrong answers, so each fact gets one source.
  3. Design retrieval. Chunk size, metadata such as product and language, and a similarity threshold below which the bot does not answer.
  4. Add guardrails. System prompt, hand-off triggers, a per-visitor rate limit, and handling of visitor text that tries to change the rules, known as prompt injection.
  5. Run the evaluation set. Every collected question goes through the bot. I read the failures by hand and fix the cause, such as a document, a threshold or the prompt, then rerun the set after each change.
  6. Launch with logging on one page or section first.
  7. Review after the first weeks. We read real conversations and fix the documents behind unanswered questions.

What happens to my data and my customers' data?

The visitor's message, the recent conversation and the document chunks needed for the answer go to the model provider's API, and nothing else should.

  • Redaction. I mask email addresses, phone numbers and card-like numbers before text is sent or logged, unless the answer needs them. Pattern matching misses some formats, so retention and access limits matter too. The bot is built so that card data, passwords and API keys are not sent in prompts, and text a visitor types is masked on a best-effort basis.
  • Retention and access. Logs are kept for a period you choose, then deleted, and only named staff accounts can read them.
  • Provider terms. OpenAI and Anthropic publish data-use terms for their business APIs. Read the current ones for your plan.

The widget tells visitors they are talking to an AI. I do not claim a chatbot makes you compliant with any law; ask your own adviser what applies.

What does an AI chatbot cost to run?

Running cost depends on traffic and on the model, and the provider bills it to your account. Every message uses tokens, the pieces of text the model reads and writes. Three limits keep the bill predictable: a cap on messages and answer length per conversation, a per-visitor rate limit, and a daily spend cap with an alert before it is reached. I report the real cost per conversation from the first weeks of logs. Building is a fixed quote or $55-$65/hour, as set out on how I work.

What should I ask any AI chatbot developer before hiring?

Put these six questions to me or to anyone else.

  • Which model is used, and can it be switched without a rebuild?
  • What does the bot say when it does not know?
  • Can I see test results on my own questions before launch?
  • What does one conversation cost, and what stops a runaway bill?
  • Who reads the logs, and for how long?
  • Who owns the code, prompts and accounts at handover?

What chatbots will I not build?

I will not build a chatbot that misleads people.

  • One that pretends to be a human. It says it is an AI, and a visitor can always ask for a person.
  • Deceptive or spam uses: fake reviews, impersonation or mass unsolicited messages.
  • Medical or legal advice bots, where a wrong answer costs too much.
  • Any bot sold on a promised resolution or deflection rate. Those depend on your documents and customers, so I measure them and promise nothing.
  • A bot that refunds, cancels or changes accounts. That is agent work.

If the chatbot belongs inside your own product, see SaaS development.

Who this is for

  • Business owners who want a website chatbot to answer pre-sales questions out of office hours
  • Support leads whose queue is full of questions the knowledge base already answers
  • Hosting and SaaS companies that want a chatbot reading WHMCS or helpdesk context, read-only
  • Teams that tried a generic chat widget and watched it invent answers
  • Companies that want an internal assistant for staff policies and runbooks

What is included

  • A set of real customer questions, collected and used as the test
  • Document cleaning, chunking and embeddings stored in a vector store
  • A system prompt and written rules for what the bot may and may not say
  • Fallback behaviour: it says it does not know, then hands off with a conversation summary
  • A streaming chat widget with rate limits and retries on provider errors
  • Conversation logs with common personal-data patterns masked, plus a retention period you choose
  • Per-conversation limits, a daily spend cap and cost alerts
  • Written handover documentation and two weeks of support after delivery

How the work runs

  1. 1

    Collect the questions

    I gather the questions your customers really ask, from tickets, chat logs and sales emails, in their own wording.

  2. 2

    Prepare the documents

    We remove outdated or conflicting pages so that each fact has one source. I split what remains into chunks and index them.

  3. 3

    Build retrieval and rules

    I connect the model, write the system prompt, set the hand-off triggers and add the cost limits.

  4. 4

    Test before launch

    Your collected questions run through the bot. I send you every wrong or weak answer, we fix the cause and rerun, or we agree it is not ready.

  5. 5

    Launch and review

    The bot goes live with logging. After the first weeks I read real conversations with you, fill gaps in the documents and adjust the triggers.

Frequently asked questions

How much does a custom AI chatbot cost?

Building it is a fixed quote after a free scoping call of about 30 minutes, or $55-$65 per hour if you prefer. I send the quote within one business day. Running it is a separate cost: the model provider bills usage to your account, and it depends on traffic and the model. I add spending limits and alerts so that it stays predictable.

Which AI model or provider will you use?

OpenAI or Anthropic models, chosen by testing both on your own questions rather than by brand. I keep the model behind a thin adapter in the code, so that switching later means changing a setting and rerunning the tests, not rebuilding the chatbot. I will tell you if a cheaper model is good enough for your questions.

Can the chatbot learn from my website?

It can read your website, but it does not learn in the sense of being retrained. I fetch your pages, clean them, cut them into chunks and index them, and the bot looks up the closest chunks for every question. When a page changes, the index is refreshed. Out-of-date pages give out-of-date answers, so the pages matter more than the model.

Will the chatbot make things up?

It can, and nobody honest can promise it never will. I reduce the chance: it is built to answer only from retrieved text, to show the source, and to say it does not know when nothing relevant is found. Before launch I run your real questions through it and read the failures. After launch, the logs show what went wrong, so it can be fixed.

Can the chatbot hand over to a human?

Yes, and I treat it as a core part of the build. The bot hands off when it has no reliable source, when the topic is one you reserve for staff, or when the visitor asks for a person. It creates a ticket or email with a short summary of the conversation. Outside staffed hours it says so and states your normal reply time.

Can it connect to WHMCS or my helpdesk?

WHMCS, yes, through its API with a dedicated read-only credential limited to the commands the bot needs, and with the client identified from the logged-in session. For other helpdesks it depends on whether they offer an API and what it allows. I check that on the scoping call and tell you before you commit to anything.

Who owns the chatbot when it is finished?

Who owns the code, prompts and evaluation questions is written into the quote before work starts. The provider and hosting accounts are opened in your name, so you can switch developers later. I hand over written documentation that explains how to update the documents and change the settings, and I give two weeks of support after delivery.

Related services

Ready to talk about your project?

Send the details and I reply within one business day with questions, an estimate and a plan.