Tenant isolation
Organization IDs scope repositories, artifacts, projects, incidents, reports and access decisions. Cross-tenant requests fail closed.
CrawlPanel protects stored credentials, limits access to evidence and restricts workers to authorized public targets.
Security architecture
Security is implemented across authentication, tenancy, storage, worker execution and outbound delivery—not left to one perimeter check.
Organization IDs scope repositories, artifacts, projects, incidents, reports and access decisions. Cross-tenant requests fail closed.
Credentials are encrypted at rest with tenant-bound AES-GCM and are materialized only inside workers when a check runs.
Journey screenshots apply configured masks. Website incident snapshots use a clean browser without customer cookies, monitor headers or authentication secrets.
Targets are validated before execution and every browser request is checked for unsafe schemes, ports and private addresses.
Email, Slack, Microsoft Teams, Discord, Telegram, PagerDuty and webhook deliveries are queued, retried and recorded. External alerts link to authenticated run evidence instead of attaching screenshots or traces.
Security-sensitive actions such as organization, secret and membership changes are recorded with actor and entity context.
Responsible disclosure
Send the issue privately with reproduction steps and affected scope. Please avoid accessing data that is not yours or disrupting service availability.
CrawlPanel does not currently claim SOC 2, ISO 27001 or independent penetration-test certification. Production hardening, backup restoration and infrastructure review remain launch gates and will be documented transparently as they are completed.
Try every Business feature free for 14 days. No credit card required.