Security is an important part of how Crawlability is designed and operated.
Crawlability uses established cloud infrastructure, managed database technology, authentication systems, and third-party service providers to help protect customer information.
Infrastructure Security
Crawlability is built using infrastructure and technology providers including:
- Vercel for application hosting and deployment;
- Supabase for database, authentication, backend services, and storage; and
- Amazon Web Services (AWS) for selected infrastructure and email-delivery services.
These providers maintain their own independent security and compliance programs.
Crawlability's use of a provider does not mean that the provider's certifications automatically constitute certification of Crawlability itself.
SOC 2 and ISO 27001
Crawlability is built on infrastructure provided by organizations that maintain recognized security certifications and attestations, including SOC 2 and/or ISO 27001 within the applicable scope of their own services.
For example, Vercel and Supabase maintain SOC 2 Type II programs and ISO 27001 certifications within their respective compliance boundaries. AWS maintains a broad independent cloud compliance program covering numerous security standards and certifications.
These certifications apply to the respective infrastructure providers and should not be interpreted as Crawlability holding those certifications itself.
Crawlability SOC 2 Status
Crawlability's own SOC 2 compliance program is currently in progress.
Until an independent audit and applicable attestation have been completed, Crawlability does not claim to be SOC 2 certified, SOC 2 compliant, or SOC 2 Type II attested.
Data Protection
Depending on the relevant system and provider, safeguards may include:
- encryption of information in transit using industry-standard TLS;
- encryption at rest within managed infrastructure;
- authentication controls;
- role-based or restricted access;
- managed database security;
- network and infrastructure monitoring;
- backups and resilience measures;
- environment and secret management; and
- logging and security monitoring.
Security follows a shared-responsibility model between Crawlability and its infrastructure providers.
Access Control
Access to production systems and customer information is limited to personnel or systems requiring access for legitimate operational purposes.
Administrative access is restricted and controlled according to operational requirements.
AI Provider Data Flow
Certain Crawlability measurements require information to be transmitted to third-party AI services.
Depending on the measurement, this may include:
- domains;
- URLs;
- brand names;
- competitor names;
- prompts;
- keywords; and
- public business information.
These requests may be processed by providers including:
- OpenAI;
- Google Gemini;
- Anthropic Claude; and
- Perplexity.
Customers should not submit passwords, authentication secrets, financial account information, confidential personal information, health information, or other sensitive data as AI measurement inputs.
Further details are provided in our Privacy Policy.
Payments
Payment card processing is handled through Stripe.
Crawlability is designed so that complete payment-card credentials are processed through Stripe rather than stored directly within Crawlability's application database.
Transactional emails may be delivered using Amazon Simple Email Service (AWS SES).
Security Incidents
Crawlability maintains processes intended to identify, investigate, contain, and respond to security incidents.
Where an incident results in notification obligations under applicable law, affected parties and relevant authorities will be notified as required.
Vulnerability Reporting
If you believe you have discovered a security vulnerability affecting Crawlability, please report it responsibly to: support@crawlability.ai
Please include sufficient information for us to understand and reproduce the issue.
Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate its existence, access information belonging to other users, or disrupt the Services.
Security Questions
Enterprise customers conducting vendor or security assessments may contact: support@crawlability.ai
