Data processing addendum

You are the controller of the traffic you proxy; we are your processor. This page is the addendum incorporated into the terms of service for every account. Last updated 8 August 2026.

1. Subject matter and instructions

We process API traffic you route through your proxies, for the purposes you configure and no other: forwarding it to your upstream, validating it against the OpenAPI documents you supply, and producing violation and drift reports. Your configuration - modes, sampling, retention, deletion - is your documented instruction set. We process nothing for our own purposes beyond the aggregate statistics described in the terms, which contain no personal data.

2. What we retain

Violation fingerprints and one redacted example per fingerprint per window. Never a full request or response body.

A fingerprint is the shape of a violation - operation, schema pointer, error class - not its content. The single example kept per window has field values redacted before storage; field names survive, contents do not. Authorization, Cookie and similar credential headers are stripped before a violation record is assembled. Conforming traffic is forwarded and not stored. Because request bodies may contain personal data of your users, the categories of data subjects and personal data are defined by what you choose to send through your proxies; the mechanism above bounds what of it we can hold.

3. Retention and deletion

Drift data is retained for your plan's window (7 days to 1 year) and then deleted. On account deletion or written instruction we delete your proxies promptly and purge stored data within 30 days, and confirm. After a downgrade, data is retained 30 days and then treated the same way. Backups age out on the same schedule.

4. Security measures

TLS in transit at the edge and to your upstream; tenant isolation by compiled per-tenant configuration; secrets held as references resolved at boot and redacted from output; card data never on our systems (Stripe); the fail-open design and its chaos evidence as described on the security page. Access to production is limited to people who operate it, on named accounts.

5. Sub-processors

The current list, with what each sees, is at /subprocessors. We add to it only with 30 days' notice to account owners, during which you may object; continuing to use the service after the notice period is acceptance. Each sub-processor is bound by terms no weaker than these.

6. Where processing happens

Service data is processed in the UK/EU. Where a sub-processor involves a transfer outside the UK/EEA (for example Stripe's or Resend's US operations), it is covered by the UK Addendum / EU Standard Contractual Clauses in that provider's terms.

7. Breach notification and audit

If we become aware of a personal data breach affecting your data we notify the account owner without undue delay and within 72 hours of awareness, with what we know and what we are doing. We assist with your data-subject requests and impact assessments to the extent the data we hold makes that meaningful. Once a year, on reasonable notice, you may audit our compliance with this addendum - in the first instance through our documentation and the security page's published evidence, and where that genuinely does not answer the question, by a review call.

8. The self-hosted alternative

Where even fingerprints must not leave your network, the Business tier's self-hosted data plane runs inside it, and this addendum then covers only your control-plane account data and whatever fingerprint stream you choose to enable.