Hoppa till innehåll
Menu and API reference

Guide

Security and data protection

How API keys, traffic, logs, storage and personal data are handled.

This page describes how the service actually runs in production. If you need a data processing agreement, a security annex or answers to your own questionnaire, just get in touch.

Protecting API keys

  • The key is never stored in plain text. We keep a SHA-256 hash and compare it in constant time, so a leaked database yields no usable credentials.
  • The secret is shown once, when it is issued, and cannot be recovered afterwards.
  • A client can hold several active keys at once, so rotation happens without downtime.
  • A key can be revoked immediately, and stops working on the next call.
  • Keys belong to a machine client. They create no web session, set no cookies, and cannot be used to sign in to firmainfo.se.

Traffic and access

  • All traffic goes over HTTPS.
  • The API is read-only. There are no endpoints that change data on our side.
  • Every resource requires a specific scope, so a key can be limited to exactly the datasets the integration needs.
  • Responses set Cache-Control: private, no-store, so intermediate caches do not retain the content.

Logs and retention

We log calls for support, debugging and abuse investigation. The log holds the timestamp, method, path, status code, response time, the key's public prefix and the client's IP address.

DataRetentionNotes
IP address in the request log30 daysCleared automatically after that; the row is kept without the IP
Other fields in the request log90 daysDeleted automatically by a daily job
Daily usage countersKeptAggregated figures for billing, no personal data

Personal data in the dataset

Most resources contain data about legal entities. Four scopes can contain data about natural persons: governance, person_lookup, contacts and market. They are enabled only once your organisation has accepted the current version of our data terms, and person_lookup is granted only after an individual review of the purpose.

  • The recipient becomes the data controller for the data retrieved, and is therefore responsible for the legal basis, for informing data subjects and for retention within their own product.
  • Sole traders are registered under the owner's personal identity number. The API therefore uses a public token in ordinary flows and shows the identity masked.
  • For sole traders the visiting address, coordinates and contact fields are also omitted, because the address is often a home.
  • The advertising_block field mirrors the marketing opt-out in the Statistics Sweden register and must be respected in your own marketing.

Where the data is processed

The service is operated in Sweden and the data comes from Swedish sources: Bolagsverket, Statistics Sweden, Finansinspektionen and PRV, plus GLEIF and ESMA for identifiers. We do not resell your request data and do not use it to profile your customers.

Incident handling

If you suspect a key has leaked, email us and we will revoke it and issue a new one. In an incident affecting your data we contact registered integration owners. Always include the request_id from the response when reporting a technical problem, so we can find the exact call in the log.