CrawlDriftCrawlDrift
Menu

Platform

Security

CrawlDrift observes your verified public pages and is engineered to enforce the same safety and tenant boundaries at every step.

Verified domains only

You may monitor only domains you control or are authorized to monitor. Domain verification is required before crawling begins.

A crawler that stays in its lane

Every fetch and redirect hop enforces scheme allowlists and DNS resolution checks while blocking loopback, private, link-local and metadata address ranges. Connection, header, body and decompression limits remain active.

Server-delivered HTML boundary

CrawlDrift currently monitors server-delivered HTML. Browser rendering is not included in the current release and is not silently enabled.

Polite by default

Our crawler respects robots.txt by default. Per-host concurrency and politeness limits protect your origin, and every redirect is revalidated against the same safety policy.

Tenant isolation

The workspace acts as the hard boundary for data, billing and permissions. Every query and resource check carries its tenant scope, so cross-tenant access behaves as not found.

Evidence retention

Snapshots, Evidence, attempts, audit records and other immutable observation history remain durable according to the applicable retention and plan policies.

Your credentials, protected

Sessions use opaque server-side cookies. Validation material is one-way hashed and recoverable provider credentials are encrypted. Secrets are excluded from logs, metrics and diagnostics.

Account security

Secure server-side sessions, step-up protection for sensitive actions and durable security event records support safe operations. MFA is not stated as mandatory for every customer account.

Encrypted Slack webhook

Slack incoming webhook credentials are encrypted, masked and excluded from diagnostics when that notification channel is enabled.

Support access consent

Normal Support access is read-only, Project-scoped, explicitly consented and visible in the related Support ticket with grant and revoke history.

Project-scoped Deployment API keys

Deployment keys are Project-scoped, use the deployment:write scope and are never shown in public screenshots, analytics or CI snippets.

Start monitoring your technical SEO today

Set up your first project in minutes. Verify your domain, start a crawl, and see exactly what changed without the noise.

No credit card required. Starter plan limits apply.