Trust Center

Verified controls, without certification theatre

This page describes controls present in the APIRaptor product today. It does not claim an external certification, contractual SLA or retention period that has not been formally approved.

Access and authentication

  • Dashboard sessions and API-key authentication are separate access paths.
  • API keys are displayed only through the existing controlled reveal flow and can be revoked.
  • Passkeys and two-factor authentication are available through configured authentication controls.

Request processing

  • Published service contracts define accepted content types, execution modes and request limits.
  • File services apply bounded validation before provider, queue and billing work where the service contract requires it.
  • Billing is recorded by the token ledger and the configured service billing event, not by client-side UI state.

Privacy and telemetry

  • Optional analytics is disabled until the visitor grants analytics consent.
  • Advertising storage and personalization are not enabled by the analytics-only choice.
  • Product-event payloads reject or redact known identifiers, secrets, document content and payment credentials.

Reliability and support

  • The public status page is sourced from the operational incident lifecycle.
  • Public health responses are intentionally high-level; internal checks stay in protected administration.
  • Support and commercial requests create a durable case before delivery is attempted.

Data processing and subprocessors

APIRaptor uses configured providers for payment processing, invoicing, transactional email, abuse prevention and optional analytics. Their use depends on the requested flow and current administrator configuration. The Privacy Policy remains the legal source for purposes, retention and data-subject rights; material subprocessor changes require the approved legal notice process before this page is expanded.

DPA, security and procurement requests

Request the currently available data-processing information or submit a security questionnaire. The request is stored as a durable case; never send API keys, credentials or customer documents.

Open a procurement case

Security contact: support@apiraptor.dev