It gives a verifiable answer to “how is my client’s data stored with you?”. We do not claim certificates we do not hold.
Who is this for
- Agencies who have to answer a security question from a client
- Technical owners who want to understand the access and permission model
Prerequisites
- An organization and at least one project
Step-by-step
- Organization isolation
All data is attached to an organization. Every project, URL, snapshot and change query passes organization validation; asking for another organization’s record returns 404.
- Access to evidence files
Screenshots and the HTML archive are never served through any unauthenticated path. The files only flow through API endpoints that check permission.
- Roles
Organization members get read and change rights according to their role. Team size depends on the plan.
- Share links
The token is stored as a SHA-256 hash; the plain value is returned only at creation. The link is time-limited and revocable; a request to a revoked link does not even say “revoked”, it returns a silent 404.
- Trigger tokens
Stored hashed, limited to a project or URL scope, can only start a scan, and can be revoked.
- Scan target restrictions
Only public HTTP/HTTPS addresses are scanned. localhost, private network addresses and other schemes are rejected; an internal network cannot be scanned through Crawlens’ own infrastructure.
Operational outputs
- An archive isolated per organization
- Authorized access to evidence
- Revocable share links and tokens
Plan availability
- Security behaviour does not change with the plan
- The number of team members depends on the plan (1 / 3 / 10 users)
- How long data is kept depends on the plan (7 / 90 / 180 days)
Limits and guardrails
- We have no SOC 2, ISO 27001 or similar certificate — we do not claim one
- No SSO/SAML
- No data residency (region) choice
- The audit log is not offered to customers as a surface
Expected outcome
- You can explain the access model to your client clearly
- Evidence you shared stops working when it expires
- The archive does not leave your organization
Troubleshooting paths
- If a share link returns 404 it may have expired or been revoked
- If an evidence image does not open, check that your session is still valid
- If you notice a security issue, write to us immediately