Security & Trust

Your data security isour top priority

CrawlRoo is built from the ground up with security, privacy, and compliance at its core. Your data stays in Australia, under your control, always.

Certifications & Compliance

Standards we meet and exceed

Australian Privacy Act Compliant

Full compliance with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs).

GDPR Compliant

Data subject rights, lawful processing, and cross-border transfer safeguards fully supported.

HIPAA Ready (Enterprise)

Business Associate Agreements available for healthcare organisations on Enterprise plans.

SOC 2 (In Progress)

Currently undergoing SOC 2 Type II audit for security, availability, and confidentiality.

Data Sovereignty -- Australian Region

All data processed and stored in AWS Sydney (ap-southeast-2). Data never leaves Australia.

Zero Data Retention with AI Providers

No customer data is stored, logged, or used for training by upstream AI providers.

Data Handling

How your data flows through CrawlRoo

Every step of our pipeline is designed with data sovereignty and privacy in mind. Here is exactly what happens with your data.

1
1

Website content is crawled and stored in Australian servers

Your website pages are securely fetched and processed entirely within Australian infrastructure. Raw HTML is never stored -- only clean, structured text.

2
2

Embeddings are generated via AWS Bedrock in Sydney (ap-southeast-2)

Text is converted to vector embeddings using Amazon Titan on AWS Bedrock, operating exclusively in the Sydney region. No data crosses international boundaries.

3
3

Chat queries are processed via AWS Bedrock (data never leaves Australia)

When a visitor asks a question, retrieval and response generation happen entirely within the ap-southeast-2 region using Claude on AWS Bedrock.

4
4

No customer data is used to train or fine-tune AI models

AWS Bedrock provides a contractual guarantee that your data is not used for model training. Your content remains exclusively yours.

5
5

All data is encrypted at rest and in transit

AES-256 encryption at rest, TLS 1.2+ for all data in transit. Encryption keys are managed via AWS KMS with automatic rotation.

Infrastructure Security

Enterprise-grade infrastructure

Our platform runs on hardened, audited infrastructure with multiple layers of protection at every level of the stack.

  • AWS Sydney region (ap-southeast-2) for all compute and storage
  • PostgreSQL with AES-256 encryption at rest
  • TLS 1.2+ enforced for all connections
  • Rate limiting and DDoS protection via Cloudflare
  • Request-level audit logging for all API calls
  • Automated vulnerability scanning and patching

Compliance Features

Built for regulated industries

Whether you operate in government, healthcare, or finance, CrawlRoo provides the compliance controls you need.

  • Per-customer data isolation with strict access controls
  • PII detection and automatic redaction in chat logs
  • Configurable data retention policies per organisation
  • Full audit trail for all administrative actions
  • GDPR data export and deletion on request
  • Field-level encryption for sensitive configuration data

Enterprise

Advanced security for larger organisations

For organisations with strict compliance requirements, our Enterprise plan provides additional security controls and customisation options.

Custom Data Retention

Define exactly how long data is stored and when it is purged, aligned with your internal governance policies.

On-Premise Deployment

Deploy CrawlRoo within your own infrastructure for complete control over data residency and access.

Custom BAA

Business Associate Agreements tailored to your compliance requirements, including HIPAA and sector-specific regulations.

SLA Guarantees

Contractual uptime guarantees with defined response times for support and incident resolution.

Dedicated Security Review

Pre-deployment security assessments, penetration testing coordination, and ongoing compliance reporting.

SSO Integration

SAML 2.0 and OIDC single sign-on support for seamless integration with your identity provider.

Security FAQ

Common security questions

Is my data used to train AI models?

No. CrawlRoo uses AWS Bedrock, which provides a contractual guarantee that customer data is never used to train or fine-tune foundation models. Your website content and chat interactions remain exclusively yours and are never shared with third parties.

Where is my data stored?

All data is stored and processed in Australia, specifically in the AWS Sydney region (ap-southeast-2). This includes your crawled website content, vector embeddings, chat logs, and account data. Data never leaves Australian borders at any point in the pipeline.

Can I delete all my data?

Yes. CrawlRoo is fully GDPR compliant. You can request complete deletion of all your data at any time, including crawled content, embeddings, chat history, and account information. Deletion requests are processed within 72 hours and we provide written confirmation once complete.

Do you support SSO?

Single sign-on is available on our Enterprise plan. We support SAML 2.0 and OIDC protocols, enabling integration with identity providers such as Azure AD, Okta, Google Workspace, and others. Contact our team to discuss your requirements.

Ready to get started
with confidence?

Deploy an AI assistant you can trust. Australian-hosted, privacy-first, and built to meet your compliance requirements.

No credit card required. Australian-hosted. SOC 2 in progress.