Crawler identity
Verify, then classify.
User-agent matches are only a hint. Vendor ranges, forward-confirmed reverse DNS and request signatures supply the actual evidence.
Security posture
CrawlClick is designed so that a compromised header, retry, tenant or dependency cannot quietly become a billable insertion, duplicate payment or publisher outage.
Crawler identity
User-agent matches are only a hint. Vendor ranges, forward-confirmed reverse DNS and request signatures supply the actual evidence.
Publisher origin
Origins must be distinct verified subdomains. DNS is resolved once and private, loopback, metadata and special-use addresses are rejected before connecting.
Edge trust
A one-time site token selects the verified tenant but cannot authorize billable traffic alone. The independent platform credential stays only in the CrawlClick-controlled Worker and proxy, so a revenue recipient cannot forge network identity.
Tenant boundary
Commercial API sessions resolve to one organisation and role. Site, campaign, funding and analytics operations enforce that boundary.
Stripe boundary
Signed raw webhooks retrieve canonical Stripe objects, bind them to stored attempts, and use durable idempotency keys for refunds and payouts.
Availability
The managed edge preserves the publisher response when CrawlClick times out or refuses to serve. Monetization cannot become the site availability dependency.
Crawls, referrals and insertion events live in object storage. Serving snapshots are immutable and stateless compute reads them without contacting Postgres.
Postgres holds identities, memberships, verified sites, Stripe state, the operation outbox and one balanced transaction per settlement window. The ledger grows with money movements, not impressions.
Invite-only pilot
Selected participants receive the concrete integration checklist and can raise origin, data-flow or payments questions before enabling traffic.