Security by design

How we protect your keys

Exactly what BuildAPI does to protect your keys and your data — and what it does not claim to have.

Get Started

Secrets Never Stored Raw

Server keys are kept only as a peppered HMAC-SHA256 hash — a database copy reveals nothing usable. Passwords use bcrypt. Traffic is TLS.

Role-Based Access Control

Fine-grained permissions for teams. Control who can create keys, view logs, and manage billing.

Audit Logs

Complete activity tracking for every API call, login, and configuration change. Immutable and tamper-proof.

Two-Factor Authentication

Optional 2FA for dashboard accounts. Add an extra layer of protection for sensitive operations.

GDPR Tooling

Self-service data export and account erasure, available to every account without contacting us.

Included on every paid plan

Bot protection, on by a checkbox

Put a new site online with no links to it and no announcement. Within hours something will request /wp-login.php; within a day, /.env. None of it is interested in you, and on a quiet site it is frequently most of your traffic.

Invisible to real people

A browser answers the challenge by itself and nobody sees a puzzle, a checkbox or a delay. There is no “select all the traffic lights” here — the visitor experience is that nothing happened.

Stops the cheap attacks

Most automated traffic is a bare HTTP client that never runs a page. It fails immediately. We are honest about the limit: a determined adversary driving a real browser is not stopped by this, or by anything else cheap. Removing the volume is the win.

You hold the controls

Per key, not per account. Choose which device classes to admit, how long to hold, whether to let search engines through, and where to send a refused visitor. Off is one click and takes effect immediately.

What you can change, per key

  • On or off — instantly, without a deploy.
  • Device classes — admit desktop, tablet and mobile independently.
  • Hold duration — how long the challenge waits before it will accept an answer. A script that answers instantly did not wait.
  • Search engines — let Google, Bing and DuckDuckGo through so you stay indexed.
  • Blocked destination — where a refused visitor lands.

The dashboard also tells you when it is switched on but nothing is calling it — because the setting configures the check and the snippet is what runs it, and having one without the other looks exactly like a broken feature.

Turn it on

The whole integration

<script src="https://buildapi.app/shield.js"
        data-key="ak_live_xxxxxxxx"></script>

One tag. Everything else is a setting on the key, so changing your mind never means changing your code.

Certifications & compliance

Domain-locked keys

Bound to your domain, ownership proved by DNS or file

Signed responses

HMAC-SHA256, nonce-bound against replay

GDPR tooling

Self-service export and erasure

bcrypt

Password hashing

HMAC

Signed API replies

TOTP

Two-factor available

RBAC

Five team roles

Build on a secure foundation

Start with BuildAPI and focus on your product, not infrastructure.

Get Started