Trust center
How CrawlCheck is run
Where data lives, how long it stays, how the site is secured, how every report is timestamped, and who else touches the data. Each line is something the running system enforces, and each one can be checked from outside.
Where data lives
CrawlCheck runs as one Cloudflare Worker. Reports, measurements and accounts are stored in Cloudflare Workers KV; report evidence and archived artifacts are stored in Cloudflare R2. There is no other database and no other server. crawlcheck.io is owned by VSNARY.
How long it is kept
| What | Kept for | Why |
|---|---|---|
A shareable report at /r/<id> | 90 days | So whoever ran the scan can share it; it then expires on its own. |
| One measurement row per scanned domain | Until the domain opts out | So a re-scan can show what changed. Opt out with one robots.txt line. |
| A quote request sent through a site’s lead form | 180 days | Delivered to the business it was addressed to, then expires. |
| A comment waiting for review | 30 days | Published or discarded by a person; unreviewed ones expire. |
| Search Console and Business Profile figures you connect | 400 days | Year-on-year comparison. Read-only; disconnecting stops collection. |
| A signed-in session (customer or owner) | 12 hours | Cookies are HttpOnly, Secure and SameSite=Strict. |
| Recent requests to this site, for the owner | The last 200 requests | A rolling tail for abuse checks; never published and never exported. |
The dataset page publishes aggregates only and has never named a scanned domain. Everything a scan sends and keeps.
How the site is secured
| Control | Setting |
|---|---|
| Transport | HTTPS only. Strict-Transport-Security: max-age=31536000; includeSubDomains; preload |
| Content Security Policy | Nonce-based script-src with strict-dynamic, object-src 'none', frame-ancestors 'none', forms may post only to this site and Stripe checkout. Violations are reported to /api/csp-report. |
| Framing and sniffing | X-Frame-Options: DENY, X-Content-Type-Options: nosniff |
| Referrer and permissions | Referrer-Policy: strict-origin-when-cross-origin; camera, microphone, geolocation, USB, serial, Bluetooth, payment and topics APIs all disabled by Permissions-Policy |
| Certificates | CAA records limit issuance to six named authorities and send incident reports to hello@crawlcheck.io |
| Scanner safety | Scan requests refuse private, loopback and link-local destinations, never sign in, and never submit a form |
| Keys | A licence key is a credential. Send it in the x-crawlcheck-key or Authorization header rather than a URL, where it would land in logs; an API key can be revoked through the API at any time. |
Check any of these yourself: curl -sI https://crawlcheck.io/ prints every header above.
| Record | What it does |
|---|---|
| SPF | Only Google Workspace and Cloudflare Email may send as crawlcheck.io. |
| DKIM | Mail this service sends is signed for crawlcheck.io and checked by the receiving server. |
| DMARC | p=quarantine for the domain and every subdomain, applied to 100% of mail; aggregate reports come back to us. |
| MTA-STS and TLS-RPT | A published policy asks sending servers to use verified TLS, and TLS-RPT sends us a report of every failure. It runs in testing mode, which reports failures without refusing mail, until the reports show a clean record. |
Every report is timestamped
Each report is reduced to its measurements, hashed with SHA-256, and each day’s hashes are combined into one Merkle root that is anchored in the Bitcoin blockchain with OpenTimestamps. That proves a report existed in exactly that form on that day and has not been edited since. It does not prove the measurement was right. See the chain and download any day’s proof.
Outside services
| Service | Used for | What it receives |
|---|---|---|
| Cloudflare | Hosting, storage (KV, R2), DNS, outbound email | Everything the site stores or serves |
| Stripe | Checkout and billing | What you enter on Stripe’s own checkout page; we never see a card number |
| Google Workspace | Our mailbox, hello@crawlcheck.io | Mail you send us |
| Google APIs | PageSpeed and Chrome UX field data; Search Console and Business Profile when you connect them; Gemini for answer checks | A public URL or domain; your Google data only after you grant access |
| OpenTimestamps calendars | Anchoring the daily seal to Bitcoin | One hash per day; no report content |
| OpenStreetMap Nominatim and Photon | Turning a service-area city into coordinates | A city name |
| Wikidata and the Internet Archive | Checking an entity’s identifiers and a page’s history | A public name or URL |
Reporting a problem
Email hello@crawlcheck.io with the subject line Security report. We acknowledge within three business days. Scope, rules and safe harbour are on the security page; the machine-readable version is security.txt.
What we collect · Proof and timestamps · Security · Terms · Refunds · Who runs this