Encrypted in transit
Every request is served over HTTPS. Plain HTTP is redirected, never answered.
Early accessWe're onboarding teams in batches. The sandbox and docs are open to everyone. Request access →
Security
Verification data is sensitive. These are the controls the product is designed around.
Prototype — controls describe the target design. Formal certifications are not claimed.
Every request is served over HTTPS. Plain HTTP is redirected, never answered.
A key is shown in full only at creation. Afterwards you see a prefix and last four characters. Revoke instantly from the dashboard.
as_test_ keys only ever touch fictional sandbox data and are never billed. Live keys are scoped to live sources.
Identifiers in request logs are masked by default (ABCDE****F). The dashboard never shows a full PAN in a list view.
IDs are checked locally (format, state code, checksum) before any source is called — malformed data never leaves the edge.
Retries with an Idempotency-Key replay the original response. No duplicate source calls, no duplicate charges.
We return business records — company, tax and director data. We don't collect biometrics or individual identity documents.
Keys can be created per service, so a leaked key can be revoked without touching the rest of your stack.
Email security@apiserver.in with steps to reproduce. We acknowledge reports and keep you updated until it's fixed. Please don't test against other customers' data.
Our privacy policy explains what we process and for how long. For data in API requests you are the Data Fiduciary and we act as your processor; the full DPA is under legal review and will be published before general availability.