JavaScript is off. The country switcher and the demos need it; everything else on this page works.

WebCrew
Start free

Security

What is checked, what is stored, and where we stand on ISO 27001

Security here is a list of concrete checks and controls, written down in plain language. No tool can promise a site never gets hacked. This one makes sure you know early and have a way to act.

Dutch company · your site data and backups stay in the EU · GDPRDutch company · operating under the GDPR · support from a person

app.webcrew.ai · kettlestone.co · security
Core filescompared to WordPress 7.1 releaseunchanged
Administrators3, all known since 2024no new accounts
Elementor Pro 3.29.1known vulnerability · fixed in 3.29.2update waiting
PHP 8.3 · WordPress 7.1both currentok
SSL certificateLet's Encrypt · renews 2 Novvalid
Scanned 4 min ago · repeats during the day1 finding, 1 action

Every site, around the clock

What the scan looks at

Core file integrity

Every WordPress core file is compared against the release it claims to be. A changed file is how a fake CAPTCHA overlay or a redirect gets in.

Unknown administrators

An administrator account nobody on your team created is flagged the moment a check sees it, with the time it was added.

Known vulnerabilities per plugin

Installed plugin versions matched against the public vulnerability databases, per site, with the version that fixes each finding.

Versions and end of life

WordPress core, PHP, theme and plugins, and how far behind each one is. PHP versions approaching end of life are flagged months ahead.

Uptime from outside, 24/7

Requested from two regions around the clock, so a site that stops answering, or starts answering with something else, is noticed within minutes.

Certificates

Whether the SSL certificate is valid and when it renews. Domain expiry is coming soon.

Who can act

Monitoring runs on its own; changing a site needs a person

The connector plugin, or SSH

One plugin links a site to your dashboard when it is activated; removing it disconnects the site. Or one SSH key, scoped to the site's own user and never root, revoked from your dashboard at any time. Every action over either is in the site's log.

The assistant

Reads first, changes second. Every change takes a restore point first and is logged; undo is one click. Where you set a rule, it asks first.

Your own AI tools

Claude, ChatGPT and other MCP clients connect through a hosted endpoint with OAuth. Reading and writing are separate scopes, and writes go through the same approval queue.

Your account

Sign in with Google or GitHub, or a password. Roles per organisation, an audit log of who did what, and an export of your data on request.

When a site is compromised

A fake CAPTCHA on a client site, found by the file check, cleaned with a restore point first

Core-file integrity finds the changed file and when it changed. Over the SSH connection we help clean the site: replace the file, remove the administrator nobody created, update or remove the plugin that let the attacker in, each step after a restore point. What we never write: that a site cannot be hacked again.

Why SSH is the recommended connection
app.webcrew.ai · kettlestone.co · file check
wp-includes/load.phpcompared to WordPress 7.1unchanged
uploads/2026/08/img.phpPHP file in uploads · added 02:14foundremoved, restore point kept
administrator wp_support2created 02:14, not by your teamfoundremoved
Elementor Pro 3.29.1known vulnerability, fixed in 3.29.2updatedthe way in, closed
1,204 other filescomparedunchanged
Restore point kept before each stepNo promise the site stays clean; a record of what was done

What is stored, and where

Technical data about your sites, in the EU for EU customers

The dashboard stores what it needs to do its job. For customers in the EU, site data and backups are stored in the EU. Your data is never sold and never used to train a model.

The privacy policy
  • Uptime and health results. Probe results, scan findings and the health score, per site, over time.
  • Versions. WordPress, PHP, theme and plugin versions, and what changed between scans.
  • Approval history and restore points. Every request, draft, approval and decline, with who did it and when, and the content a change replaced.
  • Backups Coming soon. Stored in the EU for EU customers. Retention periods and the subprocessor list are part of the privacy policy.

Certification

We are working towards ISO 27001. Here is where we stand.

ISO 27001 is the international standard for an information security management system. We are building ours now and will have it audited. Until the certificate is issued we do not call ourselves certified, and this page is where you read each step as it happens.

What the track looks like

The controls that matter to you as a customer are already in place: EU storage for EU customers, one scoped key per site, an audit log of who did what, and no change to a site without a person approving it.

Updates follow here and on the roadmap. If you need a statement for a tender or a client's security questionnaire in the meantime, write to security@webcrew.ai.

  1. Scope and risk assessment What is in scope (the dashboard, the connector, the MCP server, our own infrastructure) and where the risks are.
  2. Policies and controls documented Access, change management, incident response, supplier management, business continuity. In progress.
  3. Internal audit The system tested against the standard by someone who did not build it.
  4. Certification audit By an accredited body. The certificate will be linked here the day it is issued.

The honest limit

What is promised, and what is not

If a site is compromised, we help clean it

Over the SSH connection: changed core files replaced, administrators nobody created removed, the plugin that let the attacker in updated or removed, with a restore point before each step. With the connector only, the findings and the steps are listed for you or the host. No tool can guarantee a site stays clean, and we do not write that anywhere.

It watches from outside and does not host or shield the site

WebCrew does not sit in front of your site and does not host it. It watches from outside 24/7 and checks from inside through the connector plugin or SSH. Keep your firewall plugin; it does a different job.

Found something?

Write to security@webcrew.ai. A person reads it the same day. We would rather hear it from you than read it elsewhere.

Know about the unknown administrator the moment it appears

Start free