Security
How parseAPI handles encryption, keys, payments, and your data.
Encryption
- Every request to the API and the site runs over HTTPS with TLS 1.3.
- Plaintext HTTP is not served.
Sign-in
- Sign-in is passwordless. A magic link goes to your email and expires in 24 hours.
- There is no password database.
API keys
- Secret keys stay on your server.
- Public keys go in the browser and only work from the domains you list.
- App keys ship in mobile apps and only work from the app IDs you list.
- Archive a key anytime from the dashboard. Archived keys stop working.
- Any team member can view keys. Creating, editing, and archiving them takes an admin role.
Payments
- Payments run on Stripe. Card numbers never touch our servers.
Your data
- Request logs power your Usage and Activity dashboards, then age out. Details in the Privacy Policy.
- Bulk job files and results delete 30 days after the job completes.
- Your query stream is never sold as a marketing dataset.
Compliance
- GDPR and CCPA rights are covered in the Privacy Policy. Requests go to Email.
- Our Data Processing Agreement applies to every plan. No signature dance required.
- Security questionnaires (SIG, CAIQ, your own) are answered on request: Email
Report a vulnerability
Found something? Email Email. We read everything and respond fast. Please test only against your own account and data.
Also see the Privacy Policy, DPA, and SLA. Contracts and invoice billing: Email