CrawlPact

Security

Scanning safety

CrawlPact only fetches public HTTP/HTTPS resources you specify. All outbound requests pass through a single safe-fetch module that rejects private, loopback, link-local, reserved, and cloud-metadata addresses, rejects literal IP targets, revalidates every redirect destination, and enforces timeouts, size limits, and a request cap per scan. See scanner information.

Authentication

CrawlPact supports passkeys (WebAuthn) and Google sign-in — no passwords, and no email or SMS in the authentication or recovery path. Google sign-in is verified server-side with cryptographic ID-token verification, and every Google account maps to exactly one ordinary CrawlPact account, the same as a passkey-created one; administrator accounts always require a passkey, with no Google exception. Sessions are server-side records that can be individually reviewed and revoked.

Billing

Paddle is the billing system of record. Every inbound Paddle webhook is signature-verified before processing, and duplicate or out-of-order events are handled idempotently.

Administrative access

Super Admin actions require an assigned admin role, recent authentication for sensitive actions, and are recorded in an append-only audit log with a reason, actor, and affected target.

Responsible security disclosure

Last reviewed: 2026-08-03.

Scope

This policy covers CrawlPact-owned systems and services only. It does not authorise testing of: third-party websites audited through CrawlPact, Paddle, Cloudflare infrastructure outside CrawlPact's own configuration, other users' accounts or domains, or third-party crawler operators.

Contact

info@crawlpact.com

What to include

  • A concise description of the issue
  • The affected URL or component
  • Reproduction steps
  • The security impact
  • Supporting evidence
  • Safe contact details for follow-up

Please do not send:

  • Passwords or private keys
  • Full payment-card information
  • Unnecessary personal data
  • Destructive proof-of-concept material
  • Data belonging to other users

Prohibited testing

Do not conduct, against CrawlPact's systems or any other party:

  • Denial of service or high-volume automated scanning
  • Spam or social engineering
  • Physical attacks
  • Destructive testing or data exfiltration
  • Accessing other users' data, or persistent unauthorised access
  • Public disclosure before a reasonable remediation process has completed

Response and disclosure

CrawlPact will review good-faith reports and respond when reasonably possible; no fixed response or resolution time is promised. Coordinated disclosure is preferred. CrawlPact does not currently offer a paid bug-bounty program.

Good-faith security research conducted within these published rules, against CrawlPact's own systems only, will be reviewed responsibly. CrawlPact cannot authorise testing against third-party systems, including audited websites, Paddle, or Cloudflare.

Machine-readable contact details are also published at /.well-known/security.txt per RFC 9116.

Analytics preferences

CrawlPact uses optional Google Analytics and Microsoft Clarity on public marketing pages to understand which content is useful and how visitors actually use it. Neither is used in the authenticated app or admin areas. You can accept or decline analytics without affecting the service.