scrape.ly logo
scrape.ly Trust Center Official trust center of scrape.ly

Compliance and Security Overview

scrape.ly Trust Center

Security, compliance, and trust documentation for scrape.ly. Operated by TeraShift GmbH, so your procurement and security teams have everything they need in one place.

ISO 27001 Independently certified security program
Compliant Request report →
28Policies
42Monitored controls
5Subprocessors
5Documents

Policies

Internal policies that govern how we operate and protect customer data.

View all 28
Governance6
  • Information Security & Privacy Governance
  • Risk Management
  • Compliance & Regulatory Monitoring
  • Internal Audit Procedure
  • +2 more
Security5
  • Encryption & Crypto Controls
  • Secure Configuration & Hardening
  • Physical Security & Environmental
  • Logging, Monitoring & Audit
  • +1 more
People4
  • Background Screening & On/Off-boarding
  • Acceptable Use & Workstation Security
  • Sanctions & Disciplinary
  • Security & Privacy Awareness Training
Access3
  • Remote Access & BYOD
  • Access Control & Least Privilege
  • Authentication & Password
Data3
  • Retention & Secure Disposal
  • Data Classification & Handling
  • Information Sharing & Transfer
Operations3
  • Change & Release Management
  • Incident Response & Breach Notification
  • Backup, Business Continuity & Disaster Recovery
Vendors2
  • Third-Party Processors (Vendors)
  • Vendor & Third-Party Risk
Engineering1
  • Secure Software Development Lifecycle
Privacy1
  • Privacy & Data-Subject Rights

Security controls

Safeguards continuously monitored across our infrastructure and processes.

View all 42
Governance8
  • Asset Inventory
  • Internal Audit & Management Review
  • Legal, Regulatory & IP Compliance
  • Management Security Accountability
  • +4 more
Data Protection7
  • Data Masking
  • Data Privacy
  • Data Retention & Destruction
  • Encrypted Data at Rest
  • +3 more
Infrastructure5
  • Configuration & Patch Management
  • Endpoint Protection
  • Endpoint Security
  • Network Security
  • +1 more
People5
  • Acceptable Use
  • Disciplinary process
  • Human Resources Security
  • Personnel Security
  • +1 more
Resilience5
  • Business Continuity & ICT Readiness
  • Disaster Recovery Planning
  • Resource Capacity Management
  • Security Incident Management
  • +1 more
Access Control3
  • Access Rights
  • Credential Management
  • Segregation of duties
Monitoring3
  • Security Logging
  • Security Monitoring & Detection
  • Utility Tool monitoring
Engineering2
  • Change management
  • Secure SDLC Integration
Physical Security2
  • Physical Access Control
  • Physical & Environmental Security
Third-Party2
  • Supplier Security
  • Supplier & Third-Party Security

Subprocessors

Third parties that process data on our behalf under contractual safeguards.

View all 5
Cloudflare

We make websites, apps, and networks faster and more secure. Our developer platform is the best place to build modern apps and deliver AI initiatives.

Purpose
Edge network, DNS, WAF, and application hosting
ISO 27001PCI DSSSOC 2GDPRHIPAA
Google LLC

A suite of cloud productivity and identity management tools including email, storage, and authentication services.

Purpose
Corporate email, document storage, and identity
HIPAAISO 27001
Intercom, Inc.

A customer communications platform used for messaging, support, and engagement.

Purpose
Customer support messaging and ticketing
SOC 2ISO 27001ISO 42001HIPAAGDPRCCPA
Microsoft Corporation

A cloud-based hosting service for software development and version control using Git.

Purpose
Source code hosting and CI/CD pipelines
SOC 2SOC 3ISO 27001ISO 42001PCI DSSGDPR

Documents

Reports, certificates, and security artifacts available after NDA.

View all 5
TeraShift GmbH SOC 2 Type 2.pdf Attestation / NDA required
Ethical_IP_Sourcing_Certificate_TeraShift.pdf Certificate / NDA required
Ethical Web Data Collection Initiative Principles.pdf Principles / NDA required
TeraShift GmbH ISO 27001 Certificate.pdf Certificate / NDA required
Synthient x TeraShift GmbH x SecurityAudit.pdf Audit / NDA required