Controlled access to domain intelligence.

Customer API keys are hashed, internal credentials stay server-side, and protected endpoints require either a session or a Domain Atlas key.

  • Internal data credentials stay server-side and never appear in customer responses or UI bundles.
  • Customer API keys are shown once, stored only as SHA-256 hashes, revocable with effect on the next request, rate-limited, and tracked with aggregate usage counters.
  • Credentialed CORS, request IDs, rate limits, and browser security headers are applied at the edge, and account responses are never cached.
  • Report a vulnerability to security@domainatlas.com with the affected URL or API endpoint, steps to reproduce it, and the impact you observed.
  • We acknowledge reports within 3 business days, triage the impact, and coordinate the fix with you through security@domainatlas.com.

Questions

Does Domain Atlas expose internal data credentials?

No. Internal data credentials stay server-side and are not returned in browser bundles, customer API responses, OpenAPI output, or generated public artifacts.

How are customer API keys stored?

Customer API keys are generated by Domain Atlas, shown once, stored only as SHA-256 hashes, and tracked with aggregate usage counters. A revoked key stops working on its next request.

What security controls protect browser workflows?

Protected browser workflows use session checks, trusted-origin write guards, credentialed CORS restrictions, rate limits, request IDs, and baseline browser security headers.