Home  ·  Security & Trust
Security & trust

Built quietly,
protected seriously.

Livescraper holds public data only — never personal data, never anything behind a login. Here's exactly how we operate, store and dispose of what you scrape.

01

Public data, only

If a regular visitor sees it, we'll fetch it. No logins, no paywalls, no personal data, no scraping behind authentication.

02

Encrypted at rest

All exports, queues and logs live in AES-256-encrypted S3 buckets. Database fields are encrypted with KMS-managed keys.

03

Encrypted in transit

TLS 1.3 everywhere. HSTS preload, modern ciphers, A+ on SSL Labs. No mixed content anywhere on the platform.

Compliance

Standards we
operate by.

SOC 2 Type II

Audited annually since 2023.

Our latest SOC 2 Type II report is available under NDA. Email security@livescraper.com to request a copy.

GDPR

Data Processing Agreement.

EU-resident customers get a signed DPA on request. We act as a Processor; you remain Controller of any data you export.

CCPA

California compliant.

"Do Not Sell My Info" is the default for every California resident — we don't sell anyone's information, ever.

Hosting

AWS US-East-1 + Frankfurt.

Infrastructure runs in AWS regions us-east-1 and eu-central-1. Choose where your data is processed at signup.

Practices

How we keep things
boring.

Access

Least-privilege, MFA-required

All employee access uses SSO + WebAuthn. Production access is just-in-time and audited; no standing keys to anything.

Backups

Encrypted, tested, geo-redundant

Daily encrypted backups, replicated across two AWS regions. Restore drills run quarterly with documented RTO/RPO targets.

Monitoring

Anomaly detection, 24/7

Real-time intrusion detection, log aggregation, automated alerting. We page humans for anything that looks unusual.

Vendors

SOC 2 sub-processors only

Every sub-processor (AWS, Stripe, Postmark, Cloudflare, Sentry) carries SOC 2 or equivalent. Full list at privacy.html.

Incident response

1-hour disclosure SLA

Confirmed security incidents are disclosed to affected customers within 1 hour, with regulators within 72 hours where applicable.

Vulnerability disclosure

Found something? Tell us.

We run a no-fault disclosure program. Email security@livescraper.com with a description and reproduction steps.

  • We acknowledge within 24 hours
  • Triage and severity within 72 hours
  • Fix or mitigation timeline communicated up-front
  • Credit (with permission) on this page
security@livescraper.com

Need a SOC 2, DPA or pen-test report? Just ask.

Most documents are available under NDA. Tell us what your security team needs and we'll send it the same day.