Skip to main content

Browserless Trust Center

Security, Compliance & Privacy

Browserless holds independent security certifications and maintains documented operational and privacy procedures.

This page sets out those controls, what each one covers, and where the boundary sits when you run Browserless yourself.

Last updated: September 11, 2026

Compliance & Certifications

Current compliance and assurances include:

  • SOC 2 Type II
  • GDPR Compliance
  • BAA Available for Enterprise
  • Cyber Liability & Errors and Omissions Insurance
  • Data Processing Addendum (DPA) for deployments we operate

Compliance summary

Two pages for your security review.

SOC 2, GDPR, HIPAA, self-hosted.

SOC 2 scope. Our SOC 2 Type II is organization-wide. The organizational controls it covers, such as access management, change management, and incident response, apply across the company, including to the team that builds and ships the self-hosted Enterprise image. The infrastructure-hosting controls are scoped to the cloud we operate. A self-hosted deployment runs on infrastructure you control, so that infrastructure sits inside your own audit boundary rather than ours.

Security documentation is available for vendor review on request.

Security Practices

Browserless applies security best practices across infrastructure, operations, and access control.

Infrastructure Security

Browser automation runs in isolated environments.

Key measures include:

  • Secure cloud infrastructure
  • Containerized browser environments
  • Network segmentation and isolation
  • Continuous infrastructure monitoring

Access Control

Access to production systems is restricted and managed using strict security controls. The controls in this section govern Browserless staff access to Browserless systems. They do not describe access control inside a customer's self-hosted deployment, which the customer configures using API tokens and token roles.

Security controls include:

  • Least-privilege access policies
  • Multi-factor authentication (MFA)
  • Role-based access controls
  • Access logging and audit trails
  • Restricted administrative privileges

Single Sign-On & User Roles

Single sign-on and user roles are available for signing in to Browserless accounts on cloud-hosted plans, including Enterprise private deployments. Self-hosted deployments do not use Browserless account sign-in. Runtime access is authenticated with API tokens, and per-team token roles let you revoke one credential without rotating the fleet.

Encryption & Data Security

Encryption in Transit: All communication between customers and the Browserless platform is encrypted using Transport Layer Security (TLS) and secure HTTPS connections to protect data transmitted over public networks.

Encryption at Rest: Datastores containing sensitive customer data are encrypted at rest using encryption mechanisms provided by the underlying cloud infrastructure.

Secure Network Controls: Browserless infrastructure uses firewall protections and network controls that restrict unauthorized access to systems and services.

Monitoring & Incident Response

Browserless maintains documented procedures for monitoring and responding to security incidents.

Security processes include:

  • Security alerting and investigation
  • Documented incident response procedures
  • Dedicated support processes for security-related issues
  • Regular third-party penetration testing with severity-based remediation

Security incidents are handled through established operational and support workflows verified during security audits.

Privacy & Data Protection

How customer data is handled, how long it is kept, and where it sits.

GDPR Compliance

Browserless complies with the General Data Protection Regulation (GDPR) and maintains policies to support customer privacy obligations.

A Data Processing Addendum (DPA) is available on Enterprise plans, for deployments we operate. For self-hosted, ask us how it applies.

Data Retention & Deletion

Browserless maintains policies and procedures governing the secure handling, retention, and deletion of customer data.

Customer data is retained only for as long as necessary to provide the service or as required to meet contractual, operational, or legal obligations. Access to stored data is restricted to authorized personnel based on job responsibilities and security policies.

When services are terminated, Browserless follows defined procedures to securely remove or delete customer data from active systems in accordance with internal data management policies and infrastructure provider capabilities.

Data retention and deletion procedures are reviewed periodically as part of Browserless's security and compliance program.

Data Privacy Governance

Browserless maintains internal accountability for data privacy practices and compliance with applicable data protection regulations. Privacy-related inquiries can be directed to security@browserless.io.

Subprocessors

Browserless uses a limited number of third-party subprocessors to support platform operations, including infrastructure hosting, payment processing, and transactional email delivery. A current list of subprocessors is available on request. To obtain a copy, please contact security@browserless.io.

Data Residency

Customer data is primarily stored in the United States via AWS, DigitalOcean, and Supabase.

Regional endpoints move execution, not storage. A regional endpoint decides where the browser itself runs. Sessions execute in the region you connect to: San Francisco, London, or Amsterdam. On the shared fleet, data that is stored or forwarded leaves the EU whichever endpoint you connect to: telemetry, request logs, session replays, saved profiles, and crawl results.

Only Amsterdam executes in the EU. Of our two European endpoints, Amsterdam sits inside the EU and London executes in the UK, which is outside it.

Keeping everything in one region. Running Browserless in your own infrastructure keeps execution and stored data together: run the container in your own EU cloud or data center and it makes no outbound calls to us. Two exceptions, both yours to configure: residential proxies and CAPTCHA solving reach external services by design, so exclude them if you need a closed network.

Where stored data lives for a private deployment we operate depends on how it is provisioned. Customers with specific data residency requirements can contact our sales team to discuss available options.

Business Continuity & Reliability

Browserless maintains operational processes for platform availability and service continuity.

Operational safeguards include:

  • A documented Business Continuity and Disaster Recovery (BCDR) plan
  • Regular testing of disaster recovery procedures
  • Executive-approved continuity plans
  • Infrastructure monitoring and reliability practices

The plan is tested periodically for readiness against service disruptions.

Vendor & Data Lifecycle Management

Browserless maintains processes for secure data handling throughout the customer lifecycle.

Lifecycle controls include:

  • Secure onboarding and integration processes
  • Defined vendor off-boarding procedures

Off-boarding procedures cover data handling and transition support when services end.

Security FAQ

Do you maintain a SOC 2 report?

Yes. Browserless maintains a SOC 2 Type II report validating the effectiveness of our security and operational controls. The report is organization-wide: its organizational controls apply across the company, while its infrastructure-hosting controls are scoped to the cloud we operate. Self-hosted deployments run inside your own audit boundary.

Are you compliant with GDPR?

Yes. Browserless complies with the General Data Protection Regulation (GDPR) and maintains privacy policies aligned with EU data protection requirements.

Can I keep my data in the EU?

Our Amsterdam endpoint runs browser sessions in the EU. London is UK infrastructure and sits outside the EU. On the shared fleet, stored account data such as logs and session replays remains in our US infrastructure even when you connect to Amsterdam. To keep execution and storage together in the EU, run Browserless in your own EU infrastructure, or ask sales how a private deployment we operate would be provisioned. See Data Residency above.

Do you support HIPAA requirements?

Yes. Browserless supports HIPAA-compatible deployments on Enterprise plans, both private deployments we operate and self-hosted. A Business Associate Agreement (BAA) can be executed with customers using these deployments to process sensitive data, including PHI.

Do you provide a Data Processing Addendum (DPA)?

Yes, on Enterprise plans, for deployments we operate. For self-hosted, ask us how it applies.

Do you have cyber liability insurance?

Yes. Browserless maintains cyber liability and errors & omissions insurance, as verified during security audits.

Do you have an incident response process?

Yes. Browserless maintains documented incident response procedures and dedicated support processes for handling security incidents.

Have you experienced any recent security breaches?

Browserless has not reported any recent breaches or security incidents related to customer data.

Do you have a disaster recovery plan?

Yes. Browserless maintains a documented Business Continuity and Disaster Recovery (BCDR) plan, which is regularly tested to ensure operational readiness.

Do you use AI or machine learning systems?

Browserless does not process customer data through AI or machine learning systems. Our platform executes browser automation as directed by your code without analyzing or learning from session content.

Responsible Disclosure

Browserless welcomes responsible security research from the community. If you believe you have discovered a security vulnerability in our platform or infrastructure, we encourage you to report it promptly.

To submit a report, please email security@browserless.io with a detailed description of the vulnerability, including steps to reproduce the issue where possible. We ask that you allow us a reasonable window to investigate and address the issue before any public disclosure.

We aim to acknowledge all reports within 72 hours and will work with reporters to establish appropriate remediation timelines. Browserless does not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.

Contact Security

For more information about how Browserless handles data and service terms, please refer to our published policies:

Privacy Policy | Terms of Service

For security questions, compliance documentation requests, or vulnerability disclosures, please contact: security@browserless.io