Access controls
- Internal access is limited by role and work need.
- Production credentials must not be shared in public channels.
- Sensitive activity may be logged for audit and investigation.
Data protection
- Public connections use HTTPS/TLS.
- Passwords are stored as hashes, not plaintext.
- API keys are shown in limited form and can be revoked from the dashboard.
- Backups and logs are treated as sensitive data.
Vulnerability reporting
Send reports to support@apiindonesia.id with a summary, reproduction steps, impact, related URL or endpoint, and a safe proof of concept. Do not access other users' data, run destructive attacks, or disrupt production services.
User responsibilities
- Store API keys on servers or in secret managers, not in public apps.
- Limit team access to dashboards and repositories.
- Rotate API keys if there is any sign of leakage.
- Use rate limits and input validation in your own applications.