How we protect your keys
Exactly what BuildAPI does to protect your keys and your data — and what it does not claim to have.
Get StartedSecrets Never Stored Raw
Server keys are kept only as a peppered HMAC-SHA256 hash — a database copy reveals nothing usable. Passwords use bcrypt. Traffic is TLS.
Role-Based Access Control
Fine-grained permissions for teams. Control who can create keys, view logs, and manage billing.
Audit Logs
Complete activity tracking for every API call, login, and configuration change. Immutable and tamper-proof.
Two-Factor Authentication
Optional 2FA for dashboard accounts. Add an extra layer of protection for sensitive operations.
GDPR Tooling
Self-service data export and account erasure, available to every account without contacting us.
Bot protection, on by a checkbox
Put a new site online with no links to it and no announcement. Within hours something will
request /wp-login.php; within a day, /.env. None of it is interested in you, and on a
quiet site it is frequently most of your traffic.
Invisible to real people
A browser answers the challenge by itself and nobody sees a puzzle, a checkbox or a delay. There is no “select all the traffic lights” here — the visitor experience is that nothing happened.
Stops the cheap attacks
Most automated traffic is a bare HTTP client that never runs a page. It fails immediately. We are honest about the limit: a determined adversary driving a real browser is not stopped by this, or by anything else cheap. Removing the volume is the win.
You hold the controls
Per key, not per account. Choose which device classes to admit, how long to hold, whether to let search engines through, and where to send a refused visitor. Off is one click and takes effect immediately.
What you can change, per key
- On or off — instantly, without a deploy.
- Device classes — admit desktop, tablet and mobile independently.
- Hold duration — how long the challenge waits before it will accept an answer. A script that answers instantly did not wait.
- Search engines — let Google, Bing and DuckDuckGo through so you stay indexed.
- Blocked destination — where a refused visitor lands.
The dashboard also tells you when it is switched on but nothing is calling it — because the setting configures the check and the snippet is what runs it, and having one without the other looks exactly like a broken feature.
Turn it onThe whole integration
<script src="https://buildapi.app/shield.js"
data-key="ak_live_xxxxxxxx"></script>One tag. Everything else is a setting on the key, so changing your mind never means changing your code.
Certifications & compliance
Domain-locked keys
Bound to your domain, ownership proved by DNS or file
Signed responses
HMAC-SHA256, nonce-bound against replay
GDPR tooling
Self-service export and erasure
bcrypt
Password hashing
HMAC
Signed API replies
TOTP
Two-factor available
RBAC
Five team roles
Build on a secure foundation
Start with BuildAPI and focus on your product, not infrastructure.
Get Started