Our Approach

Grawlr is a security validation and supplier trust-corroboration platform operated by Zeeble OÜ in Estonia. Because customers trust us with website targets, scan results, questionnaires, and compliance evidence, we treat the security of our own platform as foundational.

Our practice areas include secure development, controlled access, encryption, monitoring and logging, and coordinated vulnerability response. We prefer accurate, operational controls over marketing claims that we cannot substantiate.

Security is an ongoing process at Grawlr—not a one-time checklist. This page summarizes how we approach platform security, data protection, and responsible vulnerability handling.

Infrastructure & Hosting

Production workloads for self-service plans run in EU-based data center environments. Enterprise arrangements may include region-aware options where contractually agreed.

  • Network and host hardening appropriate to a multi-tenant SaaS service
  • TLS encryption for traffic between browsers, APIs, and our services
  • Separation of application, data, and operational responsibilities where practical
  • Backup and recovery processes to support continuity of customer operations

We use carefully selected infrastructure and payment providers under contractual data-processing obligations. Payment card data is handled by Stripe; Grawlr does not store full card numbers.

Access Control

Access to customer data and production systems is limited to authorized personnel and granted on a need-to-know basis.

  • Role-based permissions inside customer accounts (Owner, Admin, Member, Viewer, and compliance-specific capabilities where enabled)
  • Authenticated API and dashboard access with session controls
  • Administrative actions are restricted and recorded for accountability
  • Enterprise options may include additional network controls such as IP allowlisting where agreed

Data Protection

We follow data-minimization principles: we collect what is needed to operate security validation, supplier questionnaires, reporting, and billing—and no more than required for those purposes.

  • Encryption in transit (TLS) and encryption at rest for sensitive stored data
  • Customer-scoped data isolation in application logic
  • GDPR-aligned processing practices for personal data, with privacy details described in our Privacy Policy
  • Retention aligned to account lifecycle, legal obligations, and operational need

For full details on personal data handling, see our Privacy Policy.

Secure Development

Changes to the platform follow controlled development and release practices intended to reduce the chance of introducing security defects.

  • Code review and testing before production releases
  • Least-privilege design for integrations, webhooks, and public questionnaire endpoints
  • Rate limiting and tokenized access for unauthenticated public compliance forms
  • Dependency and infrastructure updates as part of ongoing maintenance

Monitoring & Audit

Operational visibility helps us detect misuse and support customer accountability.

  • Customer-facing Audit Logs record meaningful account actions for traceability
  • Service and integration events are logged to support troubleshooting and security review
  • Scan execution is scoped, rate-limited, and designed to be non-destructive by default

Responsible Disclosure

We welcome good-faith reports of security issues affecting Grawlr services. Researchers should avoid privacy violations, data destruction, and disruption of production systems.

  • Report in good faith with enough detail to reproduce the issue
  • Allow reasonable time for investigation and remediation before public disclosure
  • Do not access or exfiltrate customer data beyond what is needed to demonstrate the issue
  • Respect legal boundaries and only test systems you are authorized to assess

Please send vulnerability reports to security@grawlr.com.

Safe Testing Practices

Grawlr is built for controlled security validation. Customers remain responsible for authorizing targets, respecting applicable law, and choosing appropriate environments (for example staging before production).

  • Domain ownership verification before scanning customer websites
  • Partner website scanning requires explicit scan authorization on the partner record
  • Scoped packages, predictable execution, and no automated destructive exploitation

Product usage rules are also described in our Terms of Service.

Contact

Questions about Grawlr security practices, compliance discussions, or vulnerability reports can be directed to:

Security: security@grawlr.com

Privacy / GDPR: privacy@grawlr.com

Support: support@grawlr.com

We will respond within a reasonable timeframe. For enterprise security questionnaires or detailed assurance discussions, contact us and we will coordinate the appropriate next steps.

Need more detail for a security review?

Our team can discuss hosting, access controls, data handling, and responsible testing practices for your organization.