Trust Center · for procurement & security reviews

CamsClaw · Trust

Everything a procurement / vendor-risk team needs in one page. Last reviewed 2026-08-10.

Certifications & audits

FrameworkStatusEvidence
SOC 2 Type 1In flight — auditor engagementReport expected Q3 2026. Letter on request.
SOC 2 Type 2RoadmapFollowing Type 1, 6-month observation period.
ISO 27001RoadmapGap analysis Q4 2026.
GDPRCompliantDPA template available on request.
DPDPA 2023 (India)CompliantIndian customers: data residency available.
Independent penetration testScheduledEngagement signed; report Q3 2026.

Sub-processors

Third-party services that may process customer data in the course of providing CamsClaw.

Sub-processorPurposeData locationDPA
Netcup GmbHVPS hosting (application + database)Germany (EU)Standard contractual clauses
Cloudflare, Inc.CDN, DDoS mitigation, WAFGlobal (no data persisted)Yes
Let's Encrypt (ISRG)TLS certificate issuanceUSAPublic-good service; no PII transmitted
Cams Biometrics (parent)Gitea source controlIndiaInternal — covered by group policy
SMTP provider (configurable)Outbound email — invites, regression alertsCustomer's choice (Resend / Postmark / SES / etc.)Per-provider DPA applies
ipapi.coPublic-IP → city / region / ISP / ASN enrichmentCloud (delegated DNS)Public-IP only — never tied to personally-identifying data

Data handling

Security practices

IP enrichment & visitor transparency

CamsClaw enriches visitor IPs to provide useful context — for the visitor themselves (the "Your scanning context" panel on the homepage) and for sales follow-up on demo-request submissions.

Vulnerability disclosure

Found a security issue in CamsClaw itself (not a finding from a scan)? Email security@camsclaw.ai with a description and proof-of-concept. Our coordinated-disclosure SLAs:

Public security.txt: /.well-known/security.txt

Authorization & scope

CamsClaw scans the public-facing surface of websites. Authorization to scan a site is the scanning user's responsibility — we present no presumption of consent. For paid customers, domains added to an Organization must complete Layer-2 ownership verification before deep scans (Layer-2) or active scans (Layer-3) are permitted. Layer-3 requires an explicit, versioned consent ticket per the Terms.

Architecture

For procurement reviewers

Please email procurement@camsclaw.ai for:

Status & uptime

status.camsclaw.ai — public real-time status + 90-day historical uptime. Currently: operational.