Trust

Security & API buyer notes

Lean summary for developers and GTM teams evaluating Verifly. Authoritative detail lives in Privacy and Terms. Questions: hello@veriflyemail.com.

Transport & keys

  • All API and site traffic over HTTPS/TLS.
  • API keys use a vf_ prefix; keys are hashed at rest (SHA-256).
  • Send Authorization: Bearer vf_… — never embed keys in public repos or client-side bundles.

Data handling (verification)

  • Email verification results: cached briefly (about 24 hours), then deleted.
  • Bulk job data: retained about 30 days, then automatically deleted.
  • API request logs (endpoint, timestamp, response code): retained about 90 days for debugging and security.
  • Payment card data is processed by Stripe; Verifly does not store full card numbers.
  • Database encryption at rest. See Privacy for GDPR rights and subprocessors.

Credits (SLA-lite)

  • Prepaid credit packs — credits do not expire.
  • Only deliverable and undeliverable results consume credits (per Terms).
  • No monthly seat requirement for API access; buy packs as needed.
  • This page is not a formal uptime SLA with credits/refunds for downtime. For contractual needs, contact hello@veriflyemail.com.

Rate limits

  • API access is subject to rate limits to protect shared infrastructure (see Terms).
  • Prefer batch (≤100) or async bulk for large lists instead of tight single-email loops.
  • Exceeding limits may throttle or reject requests — back off and retry with jitter.

What we are not claiming

Verifly does not lead with a published SOC 2 report on this site. If your procurement process requires a specific attestation, email hello@veriflyemail.com and we will be honest about what we can provide today.