Skip to main content

How the pipeline data is protected

The short answer

Keys are hashed and can be pinned to scopes, IP addresses and websites. Every call is rate-limited, metered and logged, and unusual bulk use pauses the key and alerts our team. Webhooks are signed. We do not hold a SOC 2 or ISO 27001 certification.

Security

API keys

  • Keys are shown once. We store only a SHA-256 hash, so a database copy cannot be used to call the API.
  • Each key can be limited to scopes (calculators, aggregates, projects, changes, exports), to IPv4 addresses or CIDR blocks, and to the websites (origins) allowed to use it from a browser.
  • Up to five active keys per account. Revoking a key takes effect on the next request.
  • Creating or revoking a key, adding a webhook, changing coverage and accepting the licence are written to an audit log.

Security

Limits and abuse checks

  • Every key has a per-minute limit, and every address a per-minute limit across keys. Monthly quotas are metered per account.
  • Lists are paged with opaque cursors, at most 100 records a page. There is no unauthenticated bulk endpoint; the free sample is 25 records.
  • Project ids are random, not sequential. Reading single projects in bulk (more than 300 in 10 minutes), pulling unusually many records in an hour, or a burst of exports pauses the key for 15 minutes and alerts our team.
  • Every call is logged per key (path, status, record count, hashed IP) for 90 days. The IP is stored only as a salted hash.

Security

Webhooks

  • Webhook URLs must be public HTTPS addresses; private and local addresses are refused.
  • Each delivery is signed with HMAC-SHA256 and a per-webhook secret, with a timestamp, so you can reject forged or replayed calls.
  • After 10 failed deliveries in a row a webhook is switched off.

Security

Accounts and the data

  • The dashboard uses your Summitly sign-in session; keys never appear in the browser after the moment you create them.
  • Owners control billing and seats; teammates use the account's keys and alerts.
  • Each customer accepts the licence agreement (clickwrap) and we keep the version, time and a hashed IP of each acceptance.
  • Secrets such as the Stripe keys and the webhook signing key live in server environment settings, never in the code.
Found a security problem? Tell us through the contact form. Licence: /data/terms.