Security

How gstinapi.in is secured

A factual account of what protects your account, your data, and your API traffic — and an honest list of what we do not (yet) have.

Transport & network

TLS on every connection

Traffic to gstinapi.in terminates at Cloudflare with SSL/TLS set to Full (strict) — the connection from Cloudflare to our origin server is itself encrypted with a Let's Encrypt certificate, not just the leg to your browser.

Locked-down origin server

The origin firewall only allows SSH and the web server ports. Every other port is closed.

Authentication & keys

API access is per-key, not per-account

Every call to /v1/* requires an x-api-key header. You can hold more than one key at a time, so rotating a key never means downtime.

Your key is visible in your dashboard on purpose

It's stored so we can show it back to you when you need it, rather than forcing you to save it somewhere else the moment it's created. Treat it exactly like a password: never share it or commit it to a public repository, and if you think it's been exposed, delete it and generate a new one from the API Keys page.

Account passwords are hashed

Dashboard login passwords are hashed with bcrypt before storage — we never store or can see your plaintext password.

Dashboard sessions use signed, expiring tokens

Logging in issues a signed JWT that expires after 7 days. It authenticates the dashboard UI only — it is separate from your API key.

Rate limiting & abuse prevention

60 requests per minute per key

Once your account has credits or a verified email, your key is allowed 60 requests/minute on the GSTIN lookup endpoint. New, unverified signups are limited to 10/minute until they verify — this slows down exactly the accounts most likely to be abusive, not everyone.

A global limit backs every endpoint

Independent of API keys, every IP is capped at 500 requests per 15 minutes across the whole API as a blanket anti-abuse measure.

Webhooks

Every payload is signed

Each webhook request carries an X-Gstinapi-Signature header — an HMAC-SHA256 of the timestamp and body, keyed to a secret unique to that endpoint. Verify it before trusting a payload; the timestamp is included specifically so a captured request can't be replayed later.

Failing endpoints get disabled automatically

A webhook endpoint that keeps failing is disabled rather than retried forever, so a broken receiver on your side doesn't turn into a silent, indefinite retry storm on ours.

Application & payments

Standard security headers on every response

We use Helmet to set a Content-Security-Policy and the usual hardening headers (no MIME-sniffing, no third-party framing) on every response.

Cross-origin requests are allow-listed

The API only accepts browser requests from gstinapi.in itself — not an open CORS policy.

Payments never touch our servers

Card and UPI details are handled entirely by Razorpay (PCI-DSS Level 1) — we never see or store payment credentials.

Data & privacy

Aligned with the DPDP Act, 2023

We act as a Data Processor for the GSTIN lookups you run — read the full commitments (lawful basis, your rights, breach notification, our Grievance Officer) on the Privacy Policy's DPDP section.

A Data Processing Agreement is available on request

Email help@gstinapi.in and we'll send one.

What we don't have

We don't hold an ISO 27001 or SOC 2 certification. A badge we haven't earned is worse than no badge, so we're not displaying one. If a formal certification becomes a requirement for your organisation, talk to us before assuming either way.

Found a security issue?

Email help@gstinapi.in with what you found and how to reproduce it. We'll acknowledge it and follow up directly — please don't test against other customers' accounts or data.