Skip to main content
Trust

Security & compliance

Botscope sits in the request path of your site, so the reasonable first question is what it sees and what happens to it. This page answers that, including the parts that are not finished yet.

What we collect

The agent reports metadata about each request. It is deliberately a short list — everything the engine needs to reach a verdict, and nothing else.

IP address
Used for reverse-DNS verification and reputation checks. Not retained in raw form beyond the telemetry window.
User-Agent string
Matched against the known-bot catalogue.
Request path and method
What was asked for. Never the body of the request or the response.
TLS fingerprint (JA3/JA4)
Identifies the client software independently of what it claims to be.
Decision and reason code
What the engine did and why — this is what the audit trail is made of.
Timestamp
When it happened.

What we never collect

  • Request or response bodies
  • Cookies or session contents
  • Authentication tokens or credentials
  • Form input from your visitors
  • Card data — billing runs through Stripe and card numbers never reach Botscope

Where it lives

Default region
EU (Frankfurt)
Regions available
EU (Frankfurt) · US (Virginia)
Self-hosted
Available on Enterprise — the agent, the edge and the data stores run inside your own infrastructure and telemetry never leaves it.
In transit / at rest
TLS 1.2+ in transit; encrypted at rest. API keys and agent tokens are stored hashed.

How long we keep it

Traffic telemetry
30 days on Pro, up to 1 year on Enterprise
Aggregated reports
For the lifetime of the workspace
Account and billing records
Lifetime of the account plus 30 days
Audit log
Retained with the workspace and exportable at any time

Earlier deletion can be requested at any time and is honoured across every store.

Certifications

Stated plainly, including where we have not got there yet. If a procurement process needs a certification we do not hold, tell us — it is useful to know which ones are blocking deals.

SOC 2 Type II
Not certified yet
ISO/IEC 27001
Not certified yet

GDPR & data processing

Our role
Processor. You are the controller of your visitors' data; we process it on your instruction.
DPA
Available on request and signable before a trial starts.
Transfers outside the EEA
Standard Contractual Clauses, or keep the workspace in the EU region and there are none.
Data subject requests
Access, export and deletion are available from the panel; anything the panel cannot do, we do on request within 30 days.

Availability & SLA

Measured uptime
Published once we have a full quarter of measurement behind it. We would rather say that than quote a number nobody checked.
SLA
99.9% target, contractual under a signed agreement.
If Botscope is unreachable
The agent fails open: your site keeps serving traffic, protection pauses, and telemetry resumes when the connection returns. It is never a single point of failure for your site.

Sub-processors

Cloud hosting
Runs the panel, the API and the data stores
EU / US, per workspace region
Stripe
Subscription billing — card data never reaches Botscope
US / EU
Email delivery
Transactional mail: alerts, invitations, scheduled reports
EU / US

We notify customers before adding a sub-processor that touches telemetry.

Reporting a vulnerability

Send it to the contact form, marked as a vulnerability report. We acknowledge within two business days, keep you updated while we fix it, and will credit you publicly if you want that. We will not pursue anyone who reports in good faith and does not access other customers' data.

Something here blocking a review?

Security questionnaires, a signed DPA, a self-hosted deployment, or a region we do not list — ask before you start a trial rather than after.

Talk to us →