Security boundaries
CrawlVolt is browser infrastructure for legitimate agent workflows. It is not positioned as an anti-bot bypass service.
Current preview
- Initial URLs are validated against the platform SSRF policy.
- Browser action count, duration, selector size and text payloads are bounded.
- CAPTCHA solving and public file upload actions are not exposed.
- Persistent sessions store only a bounded encrypted browser cookie jar; raw credentials are not stored.
- JavaScript evaluation is off by default until browser egress is isolated from private networks.
- Difficult targets may fail or rate-limit requests; the preview does not promise universal website access.
Only automate websites and accounts you are authorized to access. Respect applicable terms, privacy requirements and rate limits.
See Authenticated flows and Proxies and difficult targets for the explicit V2 support boundaries.