Security
How we protect your data.
APILens is built around the principle that observability data should never become a security liability. We auto-redact sensitive fields at the middleware level, before data leaves your server.
[observe] POST /api/checkout"authorization": ••••••••••,Redacted"password": ••••••••,Redacted"card.number": ••••••••••,RedactedEncryption
- All data in transit is encrypted with TLS 1.2+
- Data at rest is encrypted using AES-256
- API keys are hashed (SHA-256) before storage — we never store the raw key
- HTTPS enforced on all endpoints — no HTTP fallback
Data Redaction
- Sensitive fields are auto-redacted in the middleware before data leaves your server
- Redacted keys: authorization, password, passwd, pwd, secret, token, access_token, refresh_token, id_token, api_key, apikey, x-api-key, cookie, set-cookie, credit_card, card_number, cvv, ssn, private_key
- Redaction is case-insensitive and applies to all custom fields
- You can add your own keys to the redaction list via configuration
Infrastructure
- Hosted on SOC 2-compliant infrastructure
- Database backups taken every 24 hours with 30-day retention
- Isolated per-customer data with project-level API key scoping
- No third-party analytics scripts on the dashboard
Access Controls
- Authentication via Clerk — industry-standard identity provider
- API keys are scoped per-project — compromise of one key does not affect others
- Sessions expire after inactivity
- Team members can be added per-project with role-based access (coming soon)
Data Retention
- Request logs retained for 30 days on Free and Starter plans
- Extended retention on Pro and Team plans
- You can delete all your data at any time from the dashboard settings
- On account deletion, all data is purged within 72 hours
Responsible Disclosure
If you discover a security vulnerability, please report it privately before public disclosure. We commit to responding within 72 hours and resolving confirmed issues within 14 days.
security@apilens.restLast updated: May 2025