GrabzIt Trust & Security Center
Transparency is at the core of our platform. We combine enterprise-grade security with complete data control.
Security Certifications & Compliance
We are committed to the highest standards of cyber security and data protection.
- Cyber Essentials Certified: We are officially certified under the UK Government’s Cyber Essentials scheme, demonstrating our defences against common cyber threats.
- GDPR Compliant: We are fully compliant with the General Data Protection Regulation and registered with the UK Information Commissioner's Office (Ref: ZA562571).
- PCI Standards: We do not store credit card details. All payments are processed by PCI-compliant providers (Stripe and PayPal).
Reliability & Infrastructure
Your critical business processes rely on us, so we have built a redundant, scalable infrastructure.
- Enterprise SLA: We offer a Service Level Agreement for Enterprise customers, guaranteeing 99.99% uptime (less than 4.38 minutes of downtime per month).
- Trusted Hosting: Our infrastructure is hosted by IONOS, a leading provider known for its ISO-27001 certified data centers and commitment to sustainability.
- Scalability: Our architecture uses multiple redundant systems at all layers to ensure fast, efficient responses regardless of load.
Data Location & Sovereignty
We separate data storage to optimize for both performance and local compliance.
| Service |
Data Location |
Details |
| API |
Transient |
Data is processed in real-time. Storage location depends on your caching settings. |
| Screenshot Tool |
US |
Archives are stored in a secure Wasabi bucket in the US. Metadata is stored in the UK. |
| Web Monitor |
UK |
All web monitor results and metadata are processed and stored exclusively in the United Kingdom. |
| Web Scraper |
UK |
All scrape results and metadata are processed and stored exclusively in the United Kingdom. |
Data Retention & Control
You are never locked in. We provide the tools for you to manage your data lifecycle.
-
Screenshot Tool Controls:
- The "Kill Switch": If you delete a scheduled task, all associated archives and data are immediately and permanently deleted from our servers.
- Delete on Completion: You can configure tasks to delete results immediately after they are delivered to your webhook or cloud storage.
-
Retention Timelines:
- API: Cache time is customizable from 0 minutes (instant delete) up to 12 hours.
- Screenshot Tool: Archives are available for up to 5 years for Enterprise users, but can be deleted manually at any time.
- Web Monitor: The metadata required for web monitoring is kept until deleted by the user.
- Web Scraper: Results are automatically deleted from the server after 48 hours, but can be deleted manually at any time.
Advanced Security Features
- Encryption at Rest: You can provide your own encryption keys to encrypt captures before they are stored. We do not store your keys, meaning only you can decrypt the files.
- Secure Transfers: We support SSL for all data transmission and offer secure automatic transfers to Amazon S3 and Dropbox.
- Virus Free: We monitor our systems to ensure they are free of viruses and harmful components.
- Least Privilege Access: Our support and engineering teams cannot access your capture data without your explicit permission for troubleshooting.
Responsible Disclosure: Found a security vulnerability? Please contact us.