Early accessWe're onboarding teams in batches. The sandbox and docs are open to everyone. Request access →

Skip to content
APIserver.in

Security

Boring on purpose.

Verification data is sensitive. These are the controls the product is designed around.

Prototype — controls describe the target design. Formal certifications are not claimed.

Encrypted in transit

Every request is served over HTTPS. Plain HTTP is redirected, never answered.

Keys revealed once

A key is shown in full only at creation. Afterwards you see a prefix and last four characters. Revoke instantly from the dashboard.

Test and live are separate

as_test_ keys only ever touch fictional sandbox data and are never billed. Live keys are scoped to live sources.

PII masked in logs

Identifiers in request logs are masked by default (ABCDE****F). The dashboard never shows a full PAN in a list view.

Validate before we fetch

IDs are checked locally (format, state code, checksum) before any source is called — malformed data never leaves the edge.

Idempotent retries

Retries with an Idempotency-Key replay the original response. No duplicate source calls, no duplicate charges.

Data minimisation

We return business records — company, tax and director data. We don't collect biometrics or individual identity documents.

Least privilege

Keys can be created per service, so a leaked key can be revoked without touching the rest of your stack.

Report a vulnerability

Email security@apiserver.in with steps to reproduce. We acknowledge reports and keep you updated until it's fixed. Please don't test against other customers' data.

Data processing

Our privacy policy explains what we process and for how long. For data in API requests you are the Data Fiduciary and we act as your processor; the full DPA is under legal review and will be published before general availability.