Security & Privacy

Your data security and privacy are our top priorities. We implement bank-grade security measures to protect your information.

Enterprise-Grade Security

HTTPS/TLS 1.3

All API communications encrypted with latest TLS protocols

API Key Auth

Secure token-based authentication for all API requests

Encrypted at Rest

Credentials and stored data encrypted with AES-256

Minimal Data Collection

We store your account email and API usage records — nothing more. We honour deletion requests.

Data Protection

Encryption at Rest

All stored data encrypted using AES-256

Encryption in Transit

TLS 1.3 for all API communications

Regular Backups

Automated encrypted backups every 6 hours

Data Retention

Configurable retention policies per customer needs

Privacy Policy

Minimal Data Collection

We only collect data necessary for service operation

No Data Selling

Your data is never sold to third parties

Right to Deletion

Request account and data deletion at any time

Transparent Logging

Clear audit trails for all data access

Compliance

Your Data, On Request

Email us and we will export or delete the personal data we hold on you — your account email and API usage records.

Encryption in Transit & at Rest

TLS 1.3 for all API traffic; AES-256 for stored credentials

We are not currently SOC 2 or ISO 27001 certified, and we do not claim GDPR certification — no such certification exists, and we have not been independently audited for GDPR compliance. What we can tell you is exactly what we do: the data we collect, how it is encrypted, and how to have it deleted. If your procurement process requires a formal certification, contact us and we will share the security documentation we do have.

API Security Best Practices

Recommended Practices

  • • Store API keys securely (never in source code)
  • • Use environment variables for API keys
  • • Implement proper error handling
  • • Monitor API usage regularly
  • • Rotate API keys periodically
  • • Use HTTPS for all API calls

Security Warnings

  • • Never expose API keys in frontend code
  • • Don't commit API keys to version control
  • • Avoid logging API keys in application logs
  • • Don't share API keys via email or chat
  • • Revoke unused or compromised keys immediately
  • • Use server-side API calls when possible

Security Questions?

Have questions about our security practices? Our team is here to help.