Enterprise Web Scraping That Passes the Review
Who can do what, and who can prove it
- Single sign on through SAML or OIDC, with SCIM provisioning so leavers lose access the day they leave.
- Roles with real separation: who may create keys, who may change schemas, who may see payloads, who may change billing.
- Per key scopes, per key rate limits and per project budgets, so one team cannot spend another team's volume.
- An audit log of every key created or revoked, every schedule changed and every export taken, with actor, time and address.
- Keys stored hashed, shown once, revocable and rotatable without downtime, because the engineer who wrote the scraper eventually leaves.
Where data lives and how long
| Control | What you get |
|---|---|
| Response retention | 24 hours on Starter, 7 days on Growth, 30 days on Scale, 90 days on Enterprise, and shorter on any plan from the account panel |
| Data residency | Processing in the European Union or the United States, with requests staying in the region they were routed to |
| Encryption | TLS in transit, encryption at rest for payloads and for stored schemas |
| Deletion on demand | One call purges every stored response for the account, and closing an account purges the rest within 30 days |
| Use of your data | Never resold, never shared with another customer, never used to build a dataset or train anything |
Your results belong to you: we act as your processor for the pages you ask us to fetch, which is written into the terms of service and detailed in the privacy policy.
The documents procurement asks for
- A data processing agreement, signed, with the subprocessor list attached.
- Standard contractual clauses where a transfer needs them.
- A security questionnaire completed by the people who run the infrastructure.
- An invoice for every billing period, available in the account.
- An SLA with service credits and a named technical contact by email.
Write to support@webscrap.com and ask for the current pack. We send what exists today rather than a promise about what will exist later.
What we commit to in writing
Scale carries a 99.9 percent uptime commitment and a response within four business hours. Enterprise adds service credits, a named contact and written escalation paths. Every plan runs on the same infrastructure: what changes above Scale is the volume and the paperwork, not the machines.
- Request level observability in the dashboard: volume, success rate, latency and blocked attempts per key and per project.
- Usage alerts before a limit is reached, so a quota error is never the first news.
- Failures reported with an identifier your support ticket can reference.
Limits we keep on purpose
The API fetches public pages only. It forwards no credentials, holds no accounts on target sites and does not attempt to view content that requires a login. Concurrency is paced per host rather than fired all at once. These limits protect your legal position as much as ours, and the reasoning is in is web scraping legal.