security
VisualSitemaps Security & Privacy Overview
Version: 1.1 (Public Summary)
Last Updated: October 2025
Audience: Enterprise customers and security reviewers
1. Introduction
VisualSitemaps safeguards customer data and credentials during private website crawls.
This document provides a high-level overview of the platform’s security, privacy, and compliance practices designed to protect sensitive client assets.
Scope
This overview covers:
-
Authentication credentials (login credentials, Basic Auth)
-
Browser cookies and session data
-
Crawled screenshot data and visual maps
-
Network and data security
-
Access controls and compliance posture
2. Platform Overview
VisualSitemaps is a cloud-based visual crawling platform that generates interactive sitemaps from high-definition screenshots.
Crawls run in isolated containers, and content is not indexed, shared, or used for AI training.
Infrastructure
-
Hosting: Heroku + Amazon Web Services (AWS)
-
Database: PostgreSQL
-
Object storage: Amazon S3
-
Compute: Containerized isolated crawlers
-
Encryption: AES-256-CBC for stored data
-
Network: HTTPS/TLS 1.2+ enforced for all traffic
3. Credential Handling
VisualSitemaps treats customer credentials with strict confidentiality.
Credentials are encrypted both in transit and at rest, used only during the crawl execution window, and purged immediately upon completion.
Encryption Controls
-
Credentials use AES-256-CBC encryption with unique initialization vectors.
-
Encryption keys derive from a secure, application-level secret.
-
All traffic to and from the platform uses HTTPS/TLS 1.2+.
-
Credentials and cookies are automatically redacted from the database after each crawl.
Automatic Purging After Crawl Completion
Upon sitemap completion:
-
All login and authentication fields are replaced with a redacted placeholder.
-
Temporary cookies are destroyed automatically.
-
No credentials are stored in logs or persistent storage.
No Credential Logging
All sensitive parameters (e.g., passwords, tokens, cookies, API keys) are systematically filtered from all application logs.
Ephemeral Cookie Storage
Transient browser session data (cookies) is stored only briefly to maintain session continuity during crawling and is automatically expired shortly after use.
4. Data Retention & Erasure
Customer-Controlled Deletion
Customers may delete sitemaps and associated screenshots at any time through the dashboard.
Deletion triggers immediate removal from primary storage and permanent deletion from all backups within 24–48 hours.
Automated Cleanup
VisualSitemaps enforces regular automated purges of obsolete records and deleted data to minimize retention and ensure compliance with data minimization principles.
Hard Deletion Workflow
Deleted records are first soft-deleted for validation and then permanently erased, including any associated files in S3 storage.
5. Encryption & Network Security
Encryption in Transit
All communication between the user’s browser, crawlers, and the VisualSitemaps platform is secured with TLS 1.2+ and HSTS enforcement to prevent downgrade or MITM attacks.
Encryption at Rest
All sensitive data (including credentials and screenshots) is stored with AES-256-CBC encryption.
AWS provides additional server-side encryption for all S3 objects and encrypted database storage.
AWS Infrastructure Compliance
VisualSitemaps benefits from AWS’s compliance certifications, including SOC 2 Type II, ISO 27001, PCI DSS, and HIPAA eligibility, ensuring physical and network-layer protection.
6. Access Control
Internal Access Restrictions
Access to production systems is limited to a small number of senior engineers under NDA and strict least-privilege access policies.
All administrative actions are logged and auditable.
Authentication Controls
VisualSitemaps enforces secure session management and optional multi-factor authentication (MFA) for internal tools.
Administrative interfaces are protected by additional authentication layers.
API Security
API keys can be created, rotated, and revoked by users at any time.
API access is time-limited and scoped per project.
Third-Party Access
No third-party subcontractors or service providers have access to customer crawl data.
7. Compliance & Privacy Posture
Data Processing Alignment
-
GDPR: Data minimization, encryption, deletion, and data portability
-
CCPA: Customer access and right-to-be-forgotten compliance
-
Data Processing Addendum (DPA): Available on request
Privacy Controls
-
No third-party tracking within private workspaces
-
Customer data remains customer-owned and fully deletable
-
Optional dedicated or private deployments for additional isolation
SOC 2 Alignment
VisualSitemaps is aligning its controls with SOC 2 Type II standards and is preparing for formal certification.
8. Customer Control & Transparency
Self-Service Data Management
Customers have full control to:
-
View and delete their data
-
Export crawls and screenshots
-
Manage retention directly from the dashboard
Crawl Isolation
Each crawl executes within a separate, sandboxed container to ensure complete isolation between customer environments.
Temporary states and caches are unique per crawl and destroyed upon completion.
9. Summary of Security Guarantees
-
Credentials encrypted with AES-256-CBC and purged after each crawl
-
Cookies and session data redacted post-completion
-
Screenshot assets deleted from S3 upon user deletion
-
TLS 1.2+ enforced across all connections
-
Hosted on AWS, inheriting encryption-at-rest and SOC 2 controls
-
Limited production access (senior engineers only, under NDA)
-
GDPR/CCPA-aligned privacy controls
-
Per-customer crawl isolation via sandbox containers
10. Contact for Security Inquiries
Security Team: [email protected]
Available upon request:
-
Security questionnaires
-
NDA execution for deeper technical review
-
Custom Data Processing Addenda (DPAs)
-
Infrastructure and compliance documentation
Document Control
This document may be updated periodically.
The most recent version is available at https://visualsitemaps.com/security.
Disclaimer
This overview summarizes VisualSitemaps’ security and privacy posture.
It is not a formal audit report. For detailed technical validation or confidential documentation, please contact the Security Team.