Trust
Security & API buyer notes
Lean summary for developers and GTM teams evaluating Verifly. Authoritative detail lives in Privacy and Terms. Questions: hello@veriflyemail.com.
Transport & keys
- All API and site traffic over HTTPS/TLS.
- API keys use a
vf_prefix; keys are hashed at rest (SHA-256). - Send
Authorization: Bearer vf_…— never embed keys in public repos or client-side bundles.
Data handling (verification)
- Email verification results: cached briefly (about 24 hours), then deleted.
- Bulk job data: retained about 30 days, then automatically deleted.
- API request logs (endpoint, timestamp, response code): retained about 90 days for debugging and security.
- Payment card data is processed by Stripe; Verifly does not store full card numbers.
- Database encryption at rest. See Privacy for GDPR rights and subprocessors.
Credits (SLA-lite)
- Prepaid credit packs — credits do not expire.
- Only deliverable and undeliverable results consume credits (per Terms).
- No monthly seat requirement for API access; buy packs as needed.
- This page is not a formal uptime SLA with credits/refunds for downtime. For contractual needs, contact hello@veriflyemail.com.
Rate limits
- API access is subject to rate limits to protect shared infrastructure (see Terms).
- Prefer batch (≤100) or async bulk for large lists instead of tight single-email loops.
- Exceeding limits may throttle or reject requests — back off and retry with jitter.
What we are not claiming
Verifly does not lead with a published SOC 2 report on this site. If your procurement process requires a specific attestation, email hello@veriflyemail.com and we will be honest about what we can provide today.