Security & compliance
Botscope sits in the request path of your site, so the reasonable first question is what it sees and what happens to it. This page answers that, including the parts that are not finished yet.
Contents
What we collect
The agent reports metadata about each request. It is deliberately a short list — everything the engine needs to reach a verdict, and nothing else.
What we never collect
- —Request or response bodies
- —Cookies or session contents
- —Authentication tokens or credentials
- —Form input from your visitors
- —Card data — billing runs through Stripe and card numbers never reach Botscope
Where it lives
- Default region
- EU (Frankfurt)
- Regions available
- EU (Frankfurt) · US (Virginia)
- Self-hosted
- Available on Enterprise — the agent, the edge and the data stores run inside your own infrastructure and telemetry never leaves it.
- In transit / at rest
- TLS 1.2+ in transit; encrypted at rest. API keys and agent tokens are stored hashed.
How long we keep it
Earlier deletion can be requested at any time and is honoured across every store.
Certifications
Stated plainly, including where we have not got there yet. If a procurement process needs a certification we do not hold, tell us — it is useful to know which ones are blocking deals.
GDPR & data processing
- Our role
- Processor. You are the controller of your visitors' data; we process it on your instruction.
- DPA
- Available on request and signable before a trial starts.
- Transfers outside the EEA
- Standard Contractual Clauses, or keep the workspace in the EU region and there are none.
- Data subject requests
- Access, export and deletion are available from the panel; anything the panel cannot do, we do on request within 30 days.
Availability & SLA
- Measured uptime
- Published once we have a full quarter of measurement behind it. We would rather say that than quote a number nobody checked.
- SLA
- 99.9% target, contractual under a signed agreement.
- If Botscope is unreachable
- The agent fails open: your site keeps serving traffic, protection pauses, and telemetry resumes when the connection returns. It is never a single point of failure for your site.
Sub-processors
We notify customers before adding a sub-processor that touches telemetry.
Reporting a vulnerability
Send it to the contact form, marked as a vulnerability report. We acknowledge within two business days, keep you updated while we fix it, and will credit you publicly if you want that. We will not pursue anyone who reports in good faith and does not access other customers' data.
Something here blocking a review?
Security questionnaires, a signed DPA, a self-hosted deployment, or a region we do not list — ask before you start a trial rather than after.
Talk to us →