Security
API Express handles sensitive verification and financial data for hundreds of businesses across India. Our security posture is designed for the strictest enterprise requirements — meeting RBI, IRDAI, UIDAI, and DPDP Act compliance standards.
This page documents our security architecture, practices, and commitments. For enterprise clients evaluating API Express, our security team is available for direct consultation, security questionnaires, and audit support.
Security at a Glance
All traffic uses TLS 1.3. All stored data uses AES-256. No plaintext transmission or storage of sensitive data.
All data processed and stored within Indian data centres. No cross-border transfer without explicit consent.
24/7 monitoring for anomalies, unauthorized access attempts, and suspicious patterns with real-time alerts.
Least-privilege access for all employees. Multi-factor authentication mandatory. Full audit logging on every access.
1. Encryption
1.1 Encryption in transit
All API requests, dashboard sessions, and internal service communication use TLS 1.3 with strong cipher suites. Plain HTTP requests are rejected at the edge — no exceptions.
- Certificate management — Certificates rotated automatically via ACME protocol
- HSTS enabled — HTTP Strict Transport Security prevents downgrade attacks
- Forward secrecy — Ephemeral key exchange for every session
- Modern ciphers only — No legacy protocols (SSLv3, TLS 1.0/1.1) supported
1.2 Encryption at rest
All persistent data — customer records, audit logs, database backups — is encrypted at rest using AES-256. Encryption keys are managed through a dedicated key management service, rotated quarterly, and never stored with the data they protect.
1.3 Encryption of verification data
For verification APIs (Aadhaar, PAN, DL, Voter ID), sensitive input data is:
- Transmitted encrypted — TLS 1.3 end to end
- Processed in memory — Never written to disk
- Not retained — Deleted immediately after the response is returned
- Logged hashed — Audit logs contain cryptographic hashes, not raw inputs
2. Authentication & Access Control
2.1 API key authentication
Every API request is authenticated using a unique 32-character API key transmitted as a Bearer token. Keys are:
- Cryptographically generated — Using a cryptographically secure random number generator
- Scoped per environment — Sandbox and production keys are separate
- Rotatable — You can generate, rotate, and revoke keys without downtime
- Monitored — Anomalous usage patterns trigger automatic alerts
2.2 IP whitelisting
Enterprise clients can restrict API keys to specific IP addresses or CIDR ranges. Requests from non-whitelisted IPs are rejected even if the API key is valid. This is a critical defence against key theft.
2.3 Dashboard access
- Passwords — Hashed with bcrypt (cost factor 12)
- Multi-factor authentication (MFA) — Available for all accounts, mandatory for admin accounts
- Session management — Automatic logout after inactivity, session invalidated on password change
- Login alerts — Email notification on new device or location login
2.4 Employee access
Internal access to production systems follows strict principles:
- Zero-trust model — No implicit trust based on network location
- Least privilege — Employees have only the minimum access required for their role
- Mandatory MFA — All internal systems require hardware-token MFA
- Full audit logging — Every access to customer data is logged and monitored
- Just-in-time access — Sensitive access granted temporarily with approval
3. Data Protection & Privacy
3.1 India data residency
All data — customer records, API inputs, verification results, logs, and backups — is stored and processed within Indian data centres. No data is transferred outside India without explicit regulatory approval or contractual consent.
This compliance posture is required by:
- RBI data localisation directives
- IRDAI data storage requirements
- UIDAI Aadhaar storage restrictions
- DPDP Act 2023 obligations
3.2 Data minimisation
We collect and retain the minimum data required to provide the Services:
- Verification inputs — Not retained after response is returned
- API logs — 12 months rolling retention, hashed inputs
- Customer records — Retained while account is active, plus 90 days after closure
- Billing records — 7 years as required by Indian tax law
3.3 Data masking
Verification responses return only necessary fields. Sensitive information is masked at the API layer:
- Owner names partially masked (R***sh K***r)
- Aadhaar numbers not returned at all
- Full bank account numbers not returned
- Chassis and engine numbers masked where not required
4. Infrastructure Security
4.1 Hosting
API Express infrastructure runs on ISO 27001 certified cloud providers with Indian data centre regions. Our infrastructure is architected for:
- Multi-zone redundancy — No single point of failure
- Automated failover — Traffic reroutes within seconds of any zone issue
- DDoS protection — Enterprise-grade mitigation at the network edge
- WAF protection — Web Application Firewall filters malicious traffic
4.2 Network isolation
- Private VPC — All internal services run in isolated private networks
- Segmented architecture — Production, staging, and development environments are fully separated
- Encrypted internal communication — Service-to-service traffic uses mutual TLS
- No public database endpoints — All data stores are inaccessible from the public internet
4.3 Backup & disaster recovery
- Continuous backups — Every database change logged and replicated
- Encrypted backup storage — AES-256 encrypted, stored within India
- Recovery Point Objective (RPO) — Under 15 minutes
- Recovery Time Objective (RTO) — Under 2 hours
- Quarterly DR drills — Full disaster recovery exercises tested every quarter
5. Security Monitoring & Response
5.1 Continuous monitoring
Our security operations continuously monitor for:
- Unauthorized access attempts
- Unusual API usage patterns (volume, endpoints, times)
- Failed authentication attempts
- Anomalous data access by employees
- Infrastructure vulnerabilities
- Third-party dependency vulnerabilities
5.2 Incident response
We maintain a documented incident response plan covering:
- Detection — Automated alerts triggered within minutes of anomaly
- Containment — Immediate isolation of affected systems
- Investigation — Full forensic analysis of the incident
- Notification — Customers notified within 72 hours of confirmed data breach (as required by DPDP Act)
- Remediation — Root cause fix and security control updates
- Post-mortem — Internal review and, where appropriate, public disclosure
5.3 Vulnerability management
- Regular scanning — Automated vulnerability scans run daily
- Dependency monitoring — All third-party libraries tracked and updated
- Penetration testing — Annual third-party penetration testing
- Bug bounty program — See Responsible Disclosure below
6. Compliance & Certifications
6.1 Current compliance posture
| Standard | Status |
|---|---|
| DPDP Act 2023 (India) | Compliant |
| RBI KYC Master Directions | Compliant |
| Aadhaar Act / UIDAI guidelines | Compliant |
| IRDAI data storage requirements | Compliant |
| ISO 27001 aligned | Aligned (certification in progress) |
| SOC 2 Type II | Aligned (certification in progress) |
| PCI-DSS | Card data processed by PCI-DSS Level 1 partners |
6.2 Audit support
Enterprise clients with regulatory audit requirements receive:
- Completed security questionnaires (SIG, CAIQ, or custom format)
- Documentation of security controls and compliance posture
- Reference customers for peer validation
- Direct access to our security team for audit interviews
7. Responsible Disclosure
7.1 Security research is welcome
We value the work of security researchers and welcome good-faith disclosure of vulnerabilities. If you find a security issue in our platform, we want to hear about it.
7.2 How to report
Send reports to security@apiexpress.in with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Your contact information (for follow-up)
We acknowledge every report within 72 hours and provide a resolution timeline within 7 business days.
7.3 Scope
In scope:
- API endpoints (api.apiexpress.in, sandbox.api.apiexpress.in)
- Dashboard (apiexpress.in, dashboard.apiexpress.in)
- Authentication and session management
- Data protection flaws
Out of scope:
- Social engineering attacks against employees
- Denial of service (DoS) attacks
- Third-party services we rely on
- Physical security of data centres
- Automated scanner output without proof of concept
7.4 Safe harbour
We will not pursue legal action against researchers who:
- Act in good faith
- Only access data necessary to demonstrate the vulnerability
- Do not exfiltrate or disclose customer data
- Give us reasonable time to fix the issue before public disclosure
- Do not exploit the vulnerability for personal gain
8. Security Best Practices for Customers
Your security is a shared responsibility. Here's how you can protect your account and users:
8.1 Protect your API keys
- Never commit keys to Git — Use environment variables or secret managers
- Use separate keys per environment — Sandbox and production keys should be different
- Rotate keys regularly — Every 90 days minimum, or immediately if compromised
- Enable IP whitelisting — Restrict production keys to your infrastructure's IPs
- Monitor usage — Alert on unexpected spikes or endpoints
8.2 Secure your application
- Use HTTPS everywhere — Never send API keys over HTTP
- Validate inputs — Never trust user input before sending to APIs
- Sanitise outputs — Escape any data you display from API responses
- Handle errors gracefully — Don't leak internal details in error messages
8.3 Handle user data responsibly
- Obtain consent — Explicit consent from users before submitting their data
- Minimise collection — Only collect what you actually need
- Encrypt locally — Encrypt sensitive data before sending to any API
- Retain appropriately — Don't retain more than necessary, per your compliance obligations
9. Contact Security Team
For security-related questions, reporting, or enterprise evaluations:
Security Team
Email: security@apiexpress.in
PGP key: Available on request
Response time: 72 hours for initial acknowledgement
Emergency contact: For active security incidents, mention "URGENT SECURITY" in subject line
For general enquiries about our platform, use our contact page. For compliance documentation and security questionnaires, contact your account manager or email security@apiexpress.in.
This Security page is updated as our practices evolve. Last reviewed October 5, 2026. We publish material security updates in our changelog.
Talk to Our Security Team
Need our security documentation, compliance attestations, or have a security questionnaire? Our team responds within 72 hours.