Security

Monitoring needs access. Access deserves strong boundaries.

CrawlPanel is designed so credentials stay hidden, evidence stays scoped and workers can reach only authorized public targets.

Security architecture

Practical controls at every boundary.

Security is implemented across authentication, tenancy, storage, worker execution and outbound delivery—not left to one perimeter check.

01

Tenant isolation

Organization IDs scope repositories, artifacts, projects, incidents, reports and access decisions. Cross-tenant requests fail closed.

02

Encrypted secrets

Credentials are encrypted at rest with tenant-bound AES-GCM and are materialized only inside workers when a check runs.

03

Evidence redaction

Passwords and configured masks are hidden from screenshots; stored console and network evidence is redacted before persistence.

04

SSRF protection

Targets are validated before execution and every browser request is checked for unsafe schemes, ports and private addresses.

05

Signed webhooks

Outbound webhooks include unique delivery IDs and timestamped, versioned HMAC signatures for consumer verification.

06

Audit trail

Security-sensitive actions such as organization, secret and membership changes are recorded with actor and entity context.

Responsible disclosure

Found something that could put customers at risk?

Send the issue privately with reproduction steps and affected scope. Please avoid accessing data that is not yours or disrupting service availability.

security@crawlpanel.com

Current launch posture

CrawlPanel does not currently claim SOC 2, ISO 27001 or independent penetration-test certification. Production hardening, backup restoration and infrastructure review remain launch gates and will be documented transparently as they are completed.

Monitor safely, with evidence kept under control.

Start your trial today. Add your first monitor in minutes.