Compliance posture
Where we are on the frameworks enterprise buyers ask about. We state status plainly: what is in place today, what is in progress, and what is on the roadmap.
SOC 2 Type II
Crawlmind is in the observation period for a SOC 2 Type II report covering Security, Availability, and Confidentiality. During this window an independent auditor evaluates our controls over time. We are not yet able to share a completed report; once it is issued it will be available to customers and active prospects under NDA. For current status, email [email protected].
GDPR & CCPA
We operate as a data processor on behalf of our customers. We offer a Data Processing Agreement, honor data-subject requests (including the right to erasure, which is implemented as account deletion that removes a user's personal data), and keep an up-to-date list of every third party that touches customer data on our sub-processors page. Personal data is retained only as long as needed and pruned on time-bound retention windows.
ISO 27001
ISO 27001 certification is on our 2026 roadmap. It is not yet in place. We will update this page when the certification process begins.
Requesting documentation
DPAs, the SOC 2 report (once issued), and other compliance artifacts are available to customers and prospects under NDA. Email [email protected] and we will respond within two business days.