How the pipeline data is protected
The short answer
Keys are hashed and can be pinned to scopes, IP addresses and websites. Every call is rate-limited, metered and logged, and unusual bulk use pauses the key and alerts our team. Webhooks are signed. We do not hold a SOC 2 or ISO 27001 certification.
Security
API keys
- Keys are shown once. We store only a SHA-256 hash, so a database copy cannot be used to call the API.
- Each key can be limited to scopes (calculators, aggregates, projects, changes, exports), to IPv4 addresses or CIDR blocks, and to the websites (origins) allowed to use it from a browser.
- Up to five active keys per account. Revoking a key takes effect on the next request.
- Creating or revoking a key, adding a webhook, changing coverage and accepting the licence are written to an audit log.
Security
Limits and abuse checks
- Every key has a per-minute limit, and every address a per-minute limit across keys. Monthly quotas are metered per account.
- Lists are paged with opaque cursors, at most 100 records a page. There is no unauthenticated bulk endpoint; the free sample is 25 records.
- Project ids are random, not sequential. Reading single projects in bulk (more than 300 in 10 minutes), pulling unusually many records in an hour, or a burst of exports pauses the key for 15 minutes and alerts our team.
- Every call is logged per key (path, status, record count, hashed IP) for 90 days. The IP is stored only as a salted hash.
Security
Webhooks
- Webhook URLs must be public HTTPS addresses; private and local addresses are refused.
- Each delivery is signed with HMAC-SHA256 and a per-webhook secret, with a timestamp, so you can reject forged or replayed calls.
- After 10 failed deliveries in a row a webhook is switched off.
Security
Accounts and the data
- The dashboard uses your Summitly sign-in session; keys never appear in the browser after the moment you create them.
- Owners control billing and seats; teammates use the account's keys and alerts.
- Each customer accepts the licence agreement (clickwrap) and we keep the version, time and a hashed IP of each acceptance.
- Secrets such as the Stripe keys and the webhook signing key live in server environment settings, never in the code.
Found a security problem? Tell us through the contact form. Licence: /data/terms.


