Security
Security at Crawle
Account, credential, payment, and reporting boundaries for Crawle.
Report a security issue
[email protected]You do not need a Crawle account to report a suspected vulnerability.
Account security
Crawle supports email and password sign-in and Google sign-in. You can turn on TOTP two-factor authentication and revoke active sessions from account settings.
- Use a unique password for your Crawle account.
- Review and revoke active sessions when you no longer recognize a device.
Credentials and connected services
Public Crawle endpoints use HTTPS. OAuth credentials for Slack and Microsoft Teams are encrypted at rest so Crawle can deliver the destinations a workspace configures.
- Disconnect a chat integration in Crawle when its access is no longer needed.
- Keep workspace access limited to the people who need it.
Payments
Stripe handles card details for Crawle subscriptions. Crawle receives billing and payment status from Stripe but does not receive or store full card numbers.
- Manage subscriptions, invoices, and cancellation from Billing settings.
- Contact support if the app cannot complete a billing task.
Security signals Crawle reports
Crawle can report passive technology and security-header signals from monitored sites. These signals help you review a site configuration. They are not exploit validation or a penetration test.
- Confirm important findings in your own security process before you act on them.
What to include in a report
- Include the affected URL or endpoint, reproducible steps, and the impact you observed.
- Do not include customer data, secrets, or exploit payloads in the first message.