Getting Started
Security
at signzy technologies , we take security seriously and strive to ensure that all our api products are secure and comply with industry standards compliance we are iso 27001 2013 certified and we have soc2 certification , ensuring that our api products meet international standards for information security management systems we adhere to international security and privacy standards, such as gdpr and pci dss with our secure apis, you can trust that your data and transactions are protected api audits and vapt signzy conducts regular internal security audits on all its apis to ensure that its security measures are up to date and effective the infosec team conducts monthly audits to identify any vulnerabilities or areas for improvement in addition to internal audits, signzy engages a third party cert in empanelled vendor to conduct yearly vulnerability assessment and penetration testing (vapt) , scans, and code reviews on all its apis these assessments help identify any potential security weaknesses and ensure that signzy products adhere to the highest security standards signzy believes in transparency and collaboration and welcomes its customers to conduct vapt on the signzy apis before going live if their compliance requires it detailed or summarized reports of signzy's internal and external audits can be shared with customers as required, giving them peace of mind that signzy apis are secure and compliant with regulatory requirements api security signzy products only accept secure https calls for all apis, which adhere to strong cipher suites defined using sha 256 with rsa encryption this ensures that all transactional data are encrypted at the source and remain encrypted throughout, to prevent unauthorized access signzy products accept only tls 1 2 for secure communication url expiration for uploaded files for added security, all files uploaded to signzy have an expiration parameter , which is set to 30 seconds by default this helps to prevent any unauthorized access to your files the expiration parameter can be explicitly specified in the inbound request if required access tokens & api keys access tokens and api keys are used to access your information and make requests on your behalf it is strongly recommended not to send your api key or password to the client side instead, use a reverse proxy to call signzy apis this ensures that your api key and password remain secure and protected if your signzy password or api key is compromised, please let us know as soon as possible so that we can disable them and create new ones to prevent any misuse of your data authorization all requests made to our apis require authorization , which is achieved through the use of access tokens these access tokens are generated for a specific user and are used to authenticate and authorize api requests users can manage their access tokens through our api management portal getting help if you have any queries regarding the security of your data and network calls, feel free to connect with us our support team is available 24/7 to assist you with any security related issues or concerns