Security
Scanning safety
CrawlPact only fetches public HTTP/HTTPS resources you specify. All outbound requests pass through a single safe-fetch module that rejects private, loopback, link-local, reserved, and cloud-metadata addresses, rejects literal IP targets, revalidates every redirect destination, and enforces timeouts, size limits, and a request cap per scan. See scanner information.
Authentication
CrawlPact supports passkeys (WebAuthn) and Google sign-in — no passwords, and no email or SMS in the authentication or recovery path. Google sign-in is verified server-side with cryptographic ID-token verification, and every Google account maps to exactly one ordinary CrawlPact account, the same as a passkey-created one; administrator accounts always require a passkey, with no Google exception. Sessions are server-side records that can be individually reviewed and revoked.
Billing
Paddle is the billing system of record. Every inbound Paddle webhook is signature-verified before processing, and duplicate or out-of-order events are handled idempotently.
Administrative access
Super Admin actions require an assigned admin role, recent authentication for sensitive actions, and are recorded in an append-only audit log with a reason, actor, and affected target.
Responsible security disclosure
Last reviewed: 2026-08-03.
Scope
This policy covers CrawlPact-owned systems and services only. It does not authorise testing of: third-party websites audited through CrawlPact, Paddle, Cloudflare infrastructure outside CrawlPact's own configuration, other users' accounts or domains, or third-party crawler operators.
Contact
What to include
- A concise description of the issue
- The affected URL or component
- Reproduction steps
- The security impact
- Supporting evidence
- Safe contact details for follow-up
Please do not send:
- Passwords or private keys
- Full payment-card information
- Unnecessary personal data
- Destructive proof-of-concept material
- Data belonging to other users
Prohibited testing
Do not conduct, against CrawlPact's systems or any other party:
- Denial of service or high-volume automated scanning
- Spam or social engineering
- Physical attacks
- Destructive testing or data exfiltration
- Accessing other users' data, or persistent unauthorised access
- Public disclosure before a reasonable remediation process has completed
Response and disclosure
CrawlPact will review good-faith reports and respond when reasonably possible; no fixed response or resolution time is promised. Coordinated disclosure is preferred. CrawlPact does not currently offer a paid bug-bounty program.
Good-faith security research conducted within these published rules, against CrawlPact's own systems only, will be reviewed responsibly. CrawlPact cannot authorise testing against third-party systems, including audited websites, Paddle, or Cloudflare.
Machine-readable contact details are also published at /.well-known/security.txt per RFC 9116.