Legal
Security
Technical measures adopted to protect user accounts and the lookups performed on the platform.
Credentials
Neither passwords nor API keys are stored in plain text. For the password, a cryptographic digest is retained; for each key, its SHA-256 digest and a masked preview allowing it to be identified in the dashboard.
Consequently, a lost key cannot be recovered, either by the user or by the company, and must be revoked and reissued.
Transport
All traffic is encrypted using TLS, both on the website and on the API. The key is transmitted in the request header and not in the URL, so that it is not recorded on intermediate servers or in browser history.
Key validity
Keys are issued with an expiry date and record their last use. The user may revoke them at any time from the dashboard, and it is advisable to review periodically any that have gone unused for an extended period.
Reporting vulnerabilities
Vulnerabilities may be reported to contacto@perusoftware.pe, setting out the steps required to reproduce them. The company appreciates being given a reasonable period to remedy them before any public disclosure, and will not take action against those who research in good faith and without compromising third-party data.
In particular, researchers are asked not to access data belonging to others, not to degrade the service and not to disclose other customers' information.