CrawlCheck

Trust center

How CrawlCheck is run

Where data lives, how long it stays, how the site is secured, how every report is timestamped, and who else touches the data. Each line is something the running system enforces, and each one can be checked from outside.

Where data lives

CrawlCheck runs as one Cloudflare Worker. Reports, measurements and accounts are stored in Cloudflare Workers KV; report evidence and archived artifacts are stored in Cloudflare R2. There is no other database and no other server. crawlcheck.io is owned by VSNARY.

How long it is kept

WhatKept forWhy
A shareable report at /r/<id>90 daysSo whoever ran the scan can share it; it then expires on its own.
One measurement row per scanned domainUntil the domain opts outSo a re-scan can show what changed. Opt out with one robots.txt line.
A quote request sent through a site’s lead form180 daysDelivered to the business it was addressed to, then expires.
A comment waiting for review30 daysPublished or discarded by a person; unreviewed ones expire.
Search Console and Business Profile figures you connect400 daysYear-on-year comparison. Read-only; disconnecting stops collection.
A signed-in session (customer or owner)12 hoursCookies are HttpOnly, Secure and SameSite=Strict.
Recent requests to this site, for the ownerThe last 200 requestsA rolling tail for abuse checks; never published and never exported.

The dataset page publishes aggregates only and has never named a scanned domain. Everything a scan sends and keeps.

How the site is secured

ControlSetting
TransportHTTPS only. Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Content Security PolicyNonce-based script-src with strict-dynamic, object-src 'none', frame-ancestors 'none', forms may post only to this site and Stripe checkout. Violations are reported to /api/csp-report.
Framing and sniffingX-Frame-Options: DENY, X-Content-Type-Options: nosniff
Referrer and permissionsReferrer-Policy: strict-origin-when-cross-origin; camera, microphone, geolocation, USB, serial, Bluetooth, payment and topics APIs all disabled by Permissions-Policy
CertificatesCAA records limit issuance to six named authorities and send incident reports to hello@crawlcheck.io
Scanner safetyScan requests refuse private, loopback and link-local destinations, never sign in, and never submit a form
KeysA licence key is a credential. Send it in the x-crawlcheck-key or Authorization header rather than a URL, where it would land in logs; an API key can be revoked through the API at any time.

Check any of these yourself: curl -sI https://crawlcheck.io/ prints every header above.

Email

RecordWhat it does
SPFOnly Google Workspace and Cloudflare Email may send as crawlcheck.io.
DKIMMail this service sends is signed for crawlcheck.io and checked by the receiving server.
DMARCp=quarantine for the domain and every subdomain, applied to 100% of mail; aggregate reports come back to us.
MTA-STS and TLS-RPTA published policy asks sending servers to use verified TLS, and TLS-RPT sends us a report of every failure. It runs in testing mode, which reports failures without refusing mail, until the reports show a clean record.

Every report is timestamped

Each report is reduced to its measurements, hashed with SHA-256, and each day’s hashes are combined into one Merkle root that is anchored in the Bitcoin blockchain with OpenTimestamps. That proves a report existed in exactly that form on that day and has not been edited since. It does not prove the measurement was right. See the chain and download any day’s proof.

Outside services

ServiceUsed forWhat it receives
CloudflareHosting, storage (KV, R2), DNS, outbound emailEverything the site stores or serves
StripeCheckout and billingWhat you enter on Stripe’s own checkout page; we never see a card number
Google WorkspaceOur mailbox, hello@crawlcheck.ioMail you send us
Google APIsPageSpeed and Chrome UX field data; Search Console and Business Profile when you connect them; Gemini for answer checksA public URL or domain; your Google data only after you grant access
OpenTimestamps calendarsAnchoring the daily seal to BitcoinOne hash per day; no report content
OpenStreetMap Nominatim and PhotonTurning a service-area city into coordinatesA city name
Wikidata and the Internet ArchiveChecking an entity’s identifiers and a page’s historyA public name or URL

Reporting a problem

Email hello@crawlcheck.io with the subject line Security report. We acknowledge within three business days. Scope, rules and safe harbour are on the security page; the machine-readable version is security.txt.

What we collect · Proof and timestamps · Security · Terms · Refunds · Who runs this