Security

Security, documented like
an engineering page.

What we store, what we don't, how auth actually works, and exactly where our compliance posture stands today. If anything here is unclear, security@richapi.ai answers.

1 Keys & auth

How it actually works.

2 Data flow & retention

What we store, and for how long.

3 Provider chain (subprocessors)

Every response names the provider that answered.

Waterfall lookups execute against licensed third-party data providers; the provider field in every response tells you which one answered. Infrastructure: AWS (API, US us-east-1), Cloudflare (MCP edge), Supabase (auth/audit), Stripe (payments), Sentry (errors, PII-scrubbed). Full sub-processor list with purposes available on request via privacy@richapi.ai while the public subprocessors page ships; changes announced 30 days ahead via changelog.

4 Reliability controls

Circuit breakers, rate limits, signed webhooks

Provider circuit breakers with auto-recovery · per-customer rate limiting with atomic accounting and refund-on-failure · idempotent retry semantics (hard fails bill nothing) · HMAC-signed webhooks (X-RichAPI-Signature) · CI test gate on every deploy · public status page with incident history: status.richapi.ai.

5 Compliance posture

The honest table.

ItemStatus today
SOC 2In progress. Type I engagement is being scoped; controls are being formalized now. Report shared on issuance — nothing claimed before it exists.
GDPREU-headquartered (Tallinn, Estonia). DPA available. Legitimate-interest assessment for B2B contact processing drafted and under counsel review. Deletion requests honored and propagated to caches: privacy@richapi.ai.
Data residencyAPI processing in AWS US (us-east-1) under the AWS DPA with EU-approved transfer safeguards; MCP edge on Cloudflare's global network. EU-region processing is on the roadmap; Enterprise residency commitments in the MSA.
Pen testScheduled within the SOC 2 program; summary available to Enterprise under NDA when complete.
PCICard data never touches our servers — Stripe-hosted checkout.

Rule we hold ourselves to: nothing appears in this table before it's true.

6 Data ethics

The paragraph every buyer quietly looks for.

RichAPI processes business-context data: professional profiles, company records, work emails. We buy from licensed providers rather than operating gray-area collection, we don't sell or republish bulk datasets, we don't build public people-directories, and we honor removal requests downstream. The enrichment industry has seen what the other path looks like — we're built to still be here in five years.

7 Responsible disclosure

Good-faith research is welcome.

security@richapi.ai · acknowledgment within 2 business days · no legal action for good-faith research · hall-of-fame credit on request. PGP key published here.