Document / 07

Security and data

Crawlens keeps an archive of your clients’ sites. This page writes down who can reach that archive and where our limits are.

Page 7/9Agencies who have to answer a security question from a clientTechnical owners who want to understand the access and permission model

Who is this for

  • Agencies who have to answer a security question from a client
  • Technical owners who want to understand the access and permission model

Prerequisites

  • An organization and at least one project

Step-by-step

  1. Organization isolation

    All data is attached to an organization. Every project, URL, snapshot and change query passes organization validation; asking for another organization’s record returns 404.

  2. Access to evidence files

    Screenshots and the HTML archive are never served through any unauthenticated path. The files only flow through API endpoints that check permission.

  3. Roles

    Organization members get read and change rights according to their role. Team size depends on the plan.

  4. Share links

    The token is stored as a SHA-256 hash; the plain value is returned only at creation. The link is time-limited and revocable; a request to a revoked link does not even say “revoked”, it returns a silent 404.

  5. Trigger tokens

    Stored hashed, limited to a project or URL scope, can only start a scan, and can be revoked.

  6. Scan target restrictions

    Only public HTTP/HTTPS addresses are scanned. localhost, private network addresses and other schemes are rejected; an internal network cannot be scanned through Crawlens’ own infrastructure.

Operational outputs

  • An archive isolated per organization
  • Authorized access to evidence
  • Revocable share links and tokens

Plan availability

  • Security behaviour does not change with the plan
  • The number of team members depends on the plan (1 / 3 / 10 users)
  • How long data is kept depends on the plan (7 / 90 / 180 days)

Limits and guardrails

  • We have no SOC 2, ISO 27001 or similar certificate — we do not claim one
  • No SSO/SAML
  • No data residency (region) choice
  • The audit log is not offered to customers as a surface

Expected outcome

  • You can explain the access model to your client clearly
  • Evidence you shared stops working when it expires
  • The archive does not leave your organization

Troubleshooting paths

  • If a share link returns 404 it may have expired or been revoked
  • If an evidence image does not open, check that your session is still valid
  • If you notice a security issue, write to us immediately

Do you have a security form to fill in?

We do not write “we do not know something we do not know”. Send the form and we will fill in what we have and send it back.

Write to us ↗