Security
Security and data handling
How we protect your API keys, your account and the requests you send. This page describes what the service does today. When something isn't in place yet, we say so.
API keys
- Stored as hashes
- Keys are generated from 24 random bytes and stored only as SHA-256 hashes. The plaintext key is never written to the database.
- Shown once
- The full key is displayed a single time, when you create it. Keep it in a secret manager; if it is lost, rotate it.
- Rotate and revoke yourself
- Create, rotate and revoke keys in the dashboard without contacting us. Rotating a key revokes the old one.
- Per-key rate limits
- Each key has its own requests-per-minute limit, set by plan. Requests over the limit get a 429 response and are not charged.
Accounts and sessions
- Password hashing
- Passwords are hashed with scrypt and a per-password random salt, compared in constant time, and must be at least 12 characters.
- No account probing
- Sign-in takes the same time for an unknown email as for a wrong password, so responses do not reveal which accounts exist.
- Session cookies
- Session cookies are HttpOnly and SameSite=Strict. Sessions are stored hashed, expire after 12 hours and end on sign-out.
- CSRF and throttling
- Account changes require a per-session CSRF token, and sign-in is throttled to 10 attempts per 10 minutes for each IP address and email.
Transport
- HTTPS with HSTS
- HTTPS responses carry Strict-Transport-Security with a two-year max-age, including subdomains.
- Security headers
- Every API response sends a Content-Security-Policy that forbids framing, X-Frame-Options: DENY, X-Content-Type-Options: nosniff and Referrer-Policy: no-referrer.
What we log
- Request metadata, not responses
- Each API request is logged with its method, path, status, duration, response size, query string and JSON body, with credential-like fields redacted. Request headers, API keys and response bodies are not stored. You can read your own history at
GET /v1/requests. - Billing you can audit
- Every response reports its cost in
x-credits-charged. Failed requests (any 4xx or 5xx response) and empty results cost 0 credits, and the ledger is available atGET /v1/billing/ledger.
The data you collect
- Published as the source shows it
- Results are returned as each source publishes them. Guest reviews, for example, carry the reviewer's display name and country when the site shows them, so treat review data as personal data under your own privacy policy.
- Your responsibility for use
- You decide what to collect and how to use it, in line with the sources' terms and the law that applies to you. See the Terms of Service.
Availability
- Public status page
- status.scrapercompany.com checks the website, the API health endpoint and sign-in every 60 seconds and publishes the history.
Not yet in place
We have not completed a third-party audit such as SOC 2, and we do not publish an uptime SLA. Account and data deletion requests are handled by our team.
If your review needs a security questionnaire or more detail on any point above, email sales@scrapercompany.com.
Start with 1,000 free credits a month
Tell us which properties, sources and engines you need. Our team sets up your account, and you create and rotate API keys yourself. The API is free during the beta.