Frequently asked questions
Security, answered plainly.
The questions that come in most often: what happens to a lost key, what we can see of your
payment details, what stops a replayed webhook, and where a certification question
belongs.
Can you recover an API key I have lost?
No, and that is the point. The database holds a keyed HMAC-SHA256 digest of the key plus its first twelve characters — not the key. Nothing in the dashboard, the admin tooling or the support inbox can reconstruct it. Regenerate the key and update your deployment; the old one stops working immediately.
Do you ever see my card number?
No. Card entry and card management happen on Stripe-hosted pages — a Stripe Checkout session and the Stripe Customer Portal. What our database holds is the Stripe customer, subscription, payment-intent and invoice identifiers, the amount in cents, the currency and the status. There is no column anywhere in the schema for a card number, an expiry or a security code.
What stops one API key from reaching endpoints it was not meant to?
Each key carries a permissions document naming the endpoint groups it may use, and that is checked on the request path rather than in the dashboard. A key can additionally be pinned to an IP address or CIDR range, and be given an expiry date. Scope narrowly and mint separate keys for development and production.
What happens if I keep getting the password wrong?
Two independent limits apply. Five login attempts per minute from one address, enforced so that an unavailable limiter refuses logins rather than removing the limit. And ten failures against one account inside the window locks that account for fifteen minutes regardless of how many addresses the attempts came from. The lock expires on its own; no support ticket is needed.
Is two-factor authentication available?
Yes, optional TOTP with an authenticator app plus one-time backup codes. When it is enabled, a correct password alone does not create a session — it produces a short-lived pending token, and the session is only issued once a valid code or backup code is accepted.
Can I audit what my keys did?
Yes. Every authenticated request is recorded with the endpoint, method, query parameters, response code, response time, client address and user agent. The dashboard lets you browse and filter that history by endpoint, status class and key, and export it as CSV — so you can reconcile a bill or spot an unfamiliar caller yourself rather than asking us to look.
How do you stop a redelivered payment webhook from being applied twice?
Credit movements are rows in an append-only ledger with a unique idempotency key, and a database trigger rejects any attempt to update or delete a row. A replayed payment event inserts nothing the second time, and a mistake is corrected with a compensating entry rather than by editing history. Your balance is the sum of that ledger.
Do you hold a security certification?
This page describes mechanisms, not certifications, and nothing on it should be read as an audit result. If a compliance programme is material to a contract you are negotiating, raise it with sales directly rather than inferring an answer from this page.
How do I make a data-protection request?
The GDPR page documents the routes for access, correction, export and erasure requests, and what each request needs to include. Data export is available to you directly from the dashboard as a JSON download.
I think I found a vulnerability. What now?
Email the security address below rather than opening a public issue or posting it. Include what you did, what happened, and the smallest reproduction you have. Please do not test against other accounts, degrade the service, or exfiltrate data to prove a point.