A factual account of what protects your account, your data, and your API traffic — and an honest list of what we do not (yet) have.
TLS on every connection
Traffic to gstinapi.in terminates at Cloudflare with SSL/TLS set to Full (strict) — the connection from Cloudflare to our origin server is itself encrypted with a Let's Encrypt certificate, not just the leg to your browser.
Locked-down origin server
The origin firewall only allows SSH and the web server ports. Every other port is closed.
API access is per-key, not per-account
Every call to /v1/* requires an x-api-key header. You can hold more than one key at a time, so rotating a key never means downtime.
Your key is visible in your dashboard on purpose
It's stored so we can show it back to you when you need it, rather than forcing you to save it somewhere else the moment it's created. Treat it exactly like a password: never share it or commit it to a public repository, and if you think it's been exposed, delete it and generate a new one from the API Keys page.
Account passwords are hashed
Dashboard login passwords are hashed with bcrypt before storage — we never store or can see your plaintext password.
Dashboard sessions use signed, expiring tokens
Logging in issues a signed JWT that expires after 7 days. It authenticates the dashboard UI only — it is separate from your API key.
60 requests per minute per key
Once your account has credits or a verified email, your key is allowed 60 requests/minute on the GSTIN lookup endpoint. New, unverified signups are limited to 10/minute until they verify — this slows down exactly the accounts most likely to be abusive, not everyone.
A global limit backs every endpoint
Independent of API keys, every IP is capped at 500 requests per 15 minutes across the whole API as a blanket anti-abuse measure.
Every payload is signed
Each webhook request carries an X-Gstinapi-Signature header — an HMAC-SHA256 of the timestamp and body, keyed to a secret unique to that endpoint. Verify it before trusting a payload; the timestamp is included specifically so a captured request can't be replayed later.
Failing endpoints get disabled automatically
A webhook endpoint that keeps failing is disabled rather than retried forever, so a broken receiver on your side doesn't turn into a silent, indefinite retry storm on ours.
Standard security headers on every response
We use Helmet to set a Content-Security-Policy and the usual hardening headers (no MIME-sniffing, no third-party framing) on every response.
Cross-origin requests are allow-listed
The API only accepts browser requests from gstinapi.in itself — not an open CORS policy.
Payments never touch our servers
Card and UPI details are handled entirely by Razorpay (PCI-DSS Level 1) — we never see or store payment credentials.
Aligned with the DPDP Act, 2023
We act as a Data Processor for the GSTIN lookups you run — read the full commitments (lawful basis, your rights, breach notification, our Grievance Officer) on the Privacy Policy's DPDP section.
A Data Processing Agreement is available on request
Email help@gstinapi.in and we'll send one.
We don't hold an ISO 27001 or SOC 2 certification. A badge we haven't earned is worse than no badge, so we're not displaying one. If a formal certification becomes a requirement for your organisation, talk to us before assuming either way.
Email help@gstinapi.in with what you found and how to reproduce it. We'll acknowledge it and follow up directly — please don't test against other customers' accounts or data.