Security

We are in your request path. That sentence shapes every design decision on this page, because an outage of ours must never become an outage of yours.

Fail-open, by construction

The gateway's one non-negotiable property: validation can fail; forwarding cannot. If the validator dies mid-request, if a spec handle is stale, if the violation pipeline stalls, if an allocation fails - the request is forwarded untouched and the violation is dropped. Observing your traffic is our job; carrying it is a duty.

This is tested, not asserted. The chaos harness is a supported switch in the shipping gateway - APIP_CHAOS injects, per request, a dying validator, a freed spec handle, a reporter that blocks forever and an allocation failure, under load. The release gate is zero failed requests with all of it turned on. Ask us for the evidence; showing it is the point of keeping the switch in the product.

What leaves your network

Violation fingerprints and one redacted example per fingerprint per window. Never a full request or response body.

A fingerprint identifies the shape of a violation - operation, schema pointer, error class - so a permanently broken endpoint produces one record, not a million. The single example kept per window has values redacted before it is stored. This sentence appears here, in the DPA, and in the sub-processor list, saying the same thing in all three places.

If shared infrastructure is more than your security review permits, a dedicated instance runs your gateway single-tenant on isolated infrastructure we operate, in the region you choose - no other customer on the same machine. It exists precisely for the reviews that require isolation.

Transport, tenancy, retention

The paperwork

The commitments on this page are contractual, not just marketing: the redaction sentence appears in the same words in the data processing addendum, retention and deletion are bound there too, everyone who touches service data is on the public sub-processor list, and the terms and privacy policy carry the rest. We are a processor under UK/EU GDPR for the traffic you proxy; service data is hosted in the UK/EU.

Reporting a vulnerability

Mail security@openapi-proxy.com. We acknowledge within one business day, and we do not consider good-faith research on your own tenant to be a terms violation.