Security
What is checked, what is stored, and where we stand on ISO 27001
Security here is a list of concrete checks and controls, written down in plain language. No tool can promise a site never gets hacked. This one makes sure you know early and have a way to act.
Dutch company · your site data and backups stay in the EU · GDPRDutch company · operating under the GDPR · support from a person
Every site, around the clock
What the scan looks at
Core file integrity
Every WordPress core file is compared against the release it claims to be. A changed file is how a fake CAPTCHA overlay or a redirect gets in.
Unknown administrators
An administrator account nobody on your team created is flagged the moment a check sees it, with the time it was added.
Known vulnerabilities per plugin
Installed plugin versions matched against the public vulnerability databases, per site, with the version that fixes each finding.
Versions and end of life
WordPress core, PHP, theme and plugins, and how far behind each one is. PHP versions approaching end of life are flagged months ahead.
Uptime from outside, 24/7
Requested from two regions around the clock, so a site that stops answering, or starts answering with something else, is noticed within minutes.
Certificates
Whether the SSL certificate is valid and when it renews. Domain expiry is coming soon.
Who can act
Monitoring runs on its own; changing a site needs a person
The connector plugin, or SSH
One plugin links a site to your dashboard when it is activated; removing it disconnects the site. Or one SSH key, scoped to the site's own user and never root, revoked from your dashboard at any time. Every action over either is in the site's log.
The assistant
Reads first, changes second. Every change takes a restore point first and is logged; undo is one click. Where you set a rule, it asks first.
Your own AI tools
Claude, ChatGPT and other MCP clients connect through a hosted endpoint with OAuth. Reading and writing are separate scopes, and writes go through the same approval queue.
Your account
Sign in with Google or GitHub, or a password. Roles per organisation, an audit log of who did what, and an export of your data on request.
When a site is compromised
A fake CAPTCHA on a client site, found by the file check, cleaned with a restore point first
Core-file integrity finds the changed file and when it changed. Over the SSH connection we help clean the site: replace the file, remove the administrator nobody created, update or remove the plugin that let the attacker in, each step after a restore point. What we never write: that a site cannot be hacked again.
Why SSH is the recommended connectionWhat is stored, and where
Technical data about your sites, in the EU for EU customers
The dashboard stores what it needs to do its job. For customers in the EU, site data and backups are stored in the EU. Your data is never sold and never used to train a model.
The privacy policy- Uptime and health results. Probe results, scan findings and the health score, per site, over time.
- Versions. WordPress, PHP, theme and plugin versions, and what changed between scans.
- Approval history and restore points. Every request, draft, approval and decline, with who did it and when, and the content a change replaced.
- Backups Coming soon. Stored in the EU for EU customers. Retention periods and the subprocessor list are part of the privacy policy.
Certification
We are working towards ISO 27001. Here is where we stand.
ISO 27001 is the international standard for an information security management system. We are building ours now and will have it audited. Until the certificate is issued we do not call ourselves certified, and this page is where you read each step as it happens.
What the track looks like
The controls that matter to you as a customer are already in place: EU storage for EU customers, one scoped key per site, an audit log of who did what, and no change to a site without a person approving it.
Updates follow here and on the roadmap. If you need a statement for a tender or a client's security questionnaire in the meantime, write to security@webcrew.ai.
- Scope and risk assessment What is in scope (the dashboard, the connector, the MCP server, our own infrastructure) and where the risks are.
- Policies and controls documented Access, change management, incident response, supplier management, business continuity. In progress.
- Internal audit The system tested against the standard by someone who did not build it.
- Certification audit By an accredited body. The certificate will be linked here the day it is issued.
The honest limit
What is promised, and what is not
If a site is compromised, we help clean it
Over the SSH connection: changed core files replaced, administrators nobody created removed, the plugin that let the attacker in updated or removed, with a restore point before each step. With the connector only, the findings and the steps are listed for you or the host. No tool can guarantee a site stays clean, and we do not write that anywhere.
It watches from outside and does not host or shield the site
WebCrew does not sit in front of your site and does not host it. It watches from outside 24/7 and checks from inside through the connector plugin or SSH. Keep your firewall plugin; it does a different job.
Found something?
Write to security@webcrew.ai. A person reads it the same day. We would rather hear it from you than read it elsewhere.