Security
What we touch, what we keep, and for how long
A tool that inspects your infrastructure should be able to answer questions about itself with the same precision it demands of you.
Crawl etiquette
Crawls declare a stable user agent, honour robots.txt by default, and are rate-limited per origin. Concurrency and depth are agreed before the first run. We do not crawl authenticated surfaces without written scope and credentials supplied through a dedicated channel.
What is captured
Response headers, status codes, timings, and the document markup of pages in scope. We do not capture screenshots of authenticated views by default, and we do not persist request bodies you send us during a session.
Personal data
Crawled pages may incidentally contain personal data. Captured artifacts are treated as confidential, are not used to train any model, and are never shared between customers. Redaction rules can be configured per origin before a run.
Access control
Audit data is scoped to the organisation that commissioned it. Internal access is role-based, logged, and limited to personnel supporting that engagement. Credentials supplied for authenticated crawls are stored encrypted and are revocable at any time.
Retention
Default retention schedule
These are defaults. Shorter periods can be set per engagement, and deletion requests are honoured across backups within the stated window.
| Artifact | Scope | Retention | Note |
|---|---|---|---|
| Response bodies | Captured pages only | 90 days | Deleted on request within 5 business days |
| Response headers | All crawled responses | 12 months | Retained for trend comparison |
| Findings & scores | Per run | 24 months | Required for historical comparison |
| Crawl logs | Request metadata | 30 days | Rotated automatically |
- ArtifactResponse bodiesScopeCaptured pages onlyRetention90 daysNoteDeleted on request within 5 business days
- ArtifactResponse headersScopeAll crawled responsesRetention12 monthsNoteRetained for trend comparison
- ArtifactFindings & scoresScopePer runRetention24 monthsNoteRequired for historical comparison
- ArtifactCrawl logsScopeRequest metadataRetention30 daysNoteRotated automatically
Certifications
Compliance posture
We do not list certifications we do not hold. Current attestations, subprocessor lists, and a completed security questionnaire are available on request under NDA — ask on the contact page and we will send the current pack rather than a badge.
Reviewing Obcend for procurement?
We will complete your questionnaire, share our subprocessor list, and walk your security team through the crawl architecture.