We respect your privacy.

We use strictly necessary cookies to keep you signed in and to protect against CSRF. With your permission we also use a small amount of first-party analytics to improve the product. We do not sell your data and we do not use third-party advertising trackers. See our cookie policy and privacy policy .

← Trust Center

Compliance posture

Where we are on the frameworks enterprise buyers ask about. We state status plainly: what is in place today, what is in progress, and what is on the roadmap.

SOC 2 Type II

Crawlmind is in the observation period for a SOC 2 Type II report covering Security, Availability, and Confidentiality. During this window an independent auditor evaluates our controls over time. We are not yet able to share a completed report; once it is issued it will be available to customers and active prospects under NDA. For current status, email [email protected].

GDPR & CCPA

We operate as a data processor on behalf of our customers. We offer a Data Processing Agreement, honor data-subject requests (including the right to erasure, which is implemented as account deletion that removes a user's personal data), and keep an up-to-date list of every third party that touches customer data on our sub-processors page. Personal data is retained only as long as needed and pruned on time-bound retention windows.

ISO 27001

ISO 27001 certification is on our 2026 roadmap. It is not yet in place. We will update this page when the certification process begins.

Requesting documentation

DPAs, the SOC 2 report (once issued), and other compliance artifacts are available to customers and prospects under NDA. Email [email protected] and we will respond within two business days.