Preview environment
CrawlPact

Security

Scanning safety

CrawlPact only fetches public HTTP/HTTPS resources you specify. All outbound requests pass through a single safe-fetch module that rejects private, loopback, link-local, reserved, and cloud-metadata addresses, rejects literal IP targets, revalidates every redirect destination, and enforces timeouts, size limits, and a request cap per scan. See scanner information.

Authentication

CrawlPact supports passkeys (WebAuthn) and Google sign-in — no passwords, and no email or SMS in the authentication or recovery path. Google sign-in is verified server-side with cryptographic ID-token verification, and every Google account maps to exactly one ordinary CrawlPact account, the same as a passkey-created one; administrator accounts always require a passkey, with no Google exception. Sessions are server-side records that can be individually reviewed and revoked.

Billing

Paddle is the billing system of record. Every inbound Paddle webhook is signature-verified before processing, and duplicate or out-of-order events are handled idempotently.

Administrative access

Super Admin actions require an assigned admin role, recent authentication for sensitive actions, and are recorded in an append-only audit log with a reason, actor, and affected target.

Responsible security disclosure

Last reviewed: 2026-08-03.

Scope

This policy covers CrawlPact-owned systems and services only. It does not authorise testing of: third-party websites audited through CrawlPact, Paddle, Cloudflare infrastructure outside CrawlPact's own configuration, other users' accounts or domains, or third-party crawler operators.

Contact

info@crawlpact.com

What to include

  • A concise description of the issue
  • The affected URL or component
  • Reproduction steps
  • The security impact
  • Supporting evidence
  • Safe contact details for follow-up

Please do not send:

  • Passwords or private keys
  • Full payment-card information
  • Unnecessary personal data
  • Destructive proof-of-concept material
  • Data belonging to other users

Prohibited testing

Do not conduct, against CrawlPact's systems or any other party:

  • Denial of service or high-volume automated scanning
  • Spam or social engineering
  • Physical attacks
  • Destructive testing or data exfiltration
  • Accessing other users' data, or persistent unauthorised access
  • Public disclosure before a reasonable remediation process has completed

Response and disclosure

CrawlPact will review good-faith reports and respond when reasonably possible; no fixed response or resolution time is promised. Coordinated disclosure is preferred. CrawlPact does not currently offer a paid bug-bounty program.

Good-faith security research conducted within these published rules, against CrawlPact's own systems only, will be reviewed responsibly. CrawlPact cannot authorise testing against third-party systems, including audited websites, Paddle, or Cloudflare.

Machine-readable contact details are also published at /.well-known/security.txt per RFC 9116.