Skip to content
Parcel APIs
ProductDemoDocsCoveragePricingMethodologyAccount
Request access

Security

Fail closed. Verify every boundary.

Security overview · August 30, 2026

Architecture

The marketing site is a static export. Authentication is handled by Hexclave, payments by Stripe, and transactional email by Resend. Parcel API responses are served directly by a separate non-Vercel service.

Controls

  • Short-lived session tokens and server-enforced project permissions.
  • Scoped API keys, quota checks, rate limits, structured errors, and request IDs.
  • Isolated synthetic demo storage with no production database connection.
  • Privacy suppression, source verification, and release gates before public activation.
  • Webhook signature verification, replay protection, and immutable administrative audit events before launch.

Report a vulnerability

Email security@parcelapis.com with affected URL, reproduction steps, and impact. Our machine-readable security contact provides the canonical policy location. Do not access data belonging to others, degrade service, or disclose a finding before remediation coordination.

Parcel APIs

Public parcel data, made dependable for developers.

DemoDocsCoveragePricingStatusChangelogSecurityPrivacyTermsAcceptable useContactAccount
© 2026 Parcel APIshello@parcelapis.com