Protecting your integration
Security depends on both the service and the application that connects to it. This page provides practical precautions for AstrologyAPI accounts and integrations, and explains how to request information about the services you intend to use. Contractual security commitments for covered personal data belong in the signed Data Processing Agreement.
Keep credentials private
Treat API credentials as secrets. Keep them on your server and limit access to the people and systems that need them. Do not expose secrets in browser code, public repositories, URLs, screenshots or support messages. Use the authentication method and HTTPS endpoint specified in the documentation for your product.
If you suspect that credentials have been exposed or your account has been accessed without authority, contact [email protected]. Describe the affected account and issue without including the secret itself.
Limit the information you send
Send only the fields needed for the requested endpoint. Avoid unnecessary personal information in prompts, images, floor plans and support enquiries. Check your application's logs, error reporting and analytics so that they do not inadvertently expose user inputs or credentials.
For JSON APIs, AstrologyAPI retains which API was called and success/failure status, not submitted user details. Other products have different storage rules. Read the storage and deletion page when designing your application's lifecycle and user controls.
Protect reports and record identifiers
Reports, generated readings and image or session identifiers may relate to an identifiable person. Share reports only with their intended recipients. Apply appropriate access controls in your own application and avoid putting personal report links or identifiers in public pages.
Deleting a record from one system does not remove independently stored copies. Include downloads, caches, connected clients and your own backups in your retention assessment.
Infrastructure and providers
AstrologyAPI uses AWS and Google Cloud infrastructure in India and US regions, Cloudflare for DNS and website hosting, and Cloudflare R2 and Amazon S3 for storage. AI features use multiple providers, mainly OpenAI and Gemini. See the service provider overview.
The security arrangements needed for an integration depend on its products, data and configuration. Provider security materials apply to the provider's stated scope; they do not independently certify AstrologyAPI or your application. No transmission or storage method eliminates all risk.
Report a concern
Send security concerns to [email protected] with “Security” in the subject. Include the affected service, a brief description, relevant timestamps and steps that explain the issue without exposing other people's data.
Avoid sending API secrets or full production datasets. If a report needs sensitive supporting material, ask for an appropriate way to share it. This contact route does not create a vulnerability reward programme or authorise access to accounts or data belonging to others.
Customer security review
For a security questionnaire or due-diligence request, tell us which services you are evaluating, the data involved and your requirements. Email [email protected]. Service-specific measures and any agreed incident, assistance, audit or recovery commitments must be documented in the applicable agreement.
Our DPA page explains the proposed contractual framework and request-and-sign process. It does not represent an already executed agreement or a certification.