Trust

Security

Security practices, vulnerability reporting, and user responsibilities.

Last updated
July 5, 2026
Summary
  • API Indonesia protects accounts, API keys, billing, and service infrastructure with technical and operational controls.
  • We accept responsible vulnerability reports at support@apiindonesia.id.

Access controls

  • Internal access is limited by role and work need.
  • Production credentials must not be shared in public channels.
  • Sensitive activity may be logged for audit and investigation.

Data protection

  • Public connections use HTTPS/TLS.
  • Passwords are stored as hashes, not plaintext.
  • API keys are shown in limited form and can be revoked from the dashboard.
  • Backups and logs are treated as sensitive data.

Vulnerability reporting

Send reports to support@apiindonesia.id with a summary, reproduction steps, impact, related URL or endpoint, and a safe proof of concept. Do not access other users' data, run destructive attacks, or disrupt production services.

User responsibilities

  • Store API keys on servers or in secret managers, not in public apps.
  • Limit team access to dashboards and repositories.
  • Rotate API keys if there is any sign of leakage.
  • Use rate limits and input validation in your own applications.